]> www.infradead.org Git - users/dwmw2/linux.git/commitdiff
x86/bugs: Remove duplicate Spectre cmdline option descriptions
authorJosh Poimboeuf <jpoimboe@kernel.org>
Wed, 26 Jun 2024 06:02:01 +0000 (23:02 -0700)
committerBorislav Petkov (AMD) <bp@alien8.de>
Fri, 28 Jun 2024 13:28:38 +0000 (15:28 +0200)
Duplicating the documentation of all the Spectre kernel cmdline options
in two separate files is unwieldy and error-prone.  Instead just add a
reference to kernel-parameters.txt from spectre.rst.

Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Daniel Sneddon <daniel.sneddon@linux.intel.com>
Link: https://lore.kernel.org/r/450b5f4ffe891a8cc9736ec52b0c6f225bab3f4b.1719381528.git.jpoimboe@kernel.org
Documentation/admin-guide/hw-vuln/spectre.rst

index 25a04cda4c2c054864fa1792d98d9f095ea56a17..132e0bc6007ed932c56e506b8008ee259a6dcfee 100644 (file)
@@ -592,85 +592,19 @@ Spectre variant 2
 Mitigation control on the kernel command line
 ---------------------------------------------
 
-Spectre variant 2 mitigation can be disabled or force enabled at the
-kernel command line.
+In general the kernel selects reasonable default mitigations for the
+current CPU.
 
-       nospectre_v1
+Spectre default mitigations can be disabled or changed at the kernel
+command line with the following options:
 
-               [X86,PPC] Disable mitigations for Spectre Variant 1
-               (bounds check bypass). With this option data leaks are
-               possible in the system.
+       - nospectre_v1
+       - nospectre_v2
+       - spectre_v2={option}
+       - spectre_v2_user={option}
+       - spectre_bhi={option}
 
-       nospectre_v2
-
-               [X86] Disable all mitigations for the Spectre variant 2
-               (indirect branch prediction) vulnerability. System may
-               allow data leaks with this option, which is equivalent
-               to spectre_v2=off.
-
-
-        spectre_v2=
-
-               [X86] Control mitigation of Spectre variant 2
-               (indirect branch speculation) vulnerability.
-               The default operation protects the kernel from
-               user space attacks.
-
-               on
-                       unconditionally enable, implies
-                       spectre_v2_user=on
-               off
-                       unconditionally disable, implies
-                       spectre_v2_user=off
-               auto
-                       kernel detects whether your CPU model is
-                       vulnerable
-
-               Selecting 'on' will, and 'auto' may, choose a
-               mitigation method at run time according to the
-               CPU, the available microcode, the setting of the
-               CONFIG_MITIGATION_RETPOLINE configuration option,
-               and the compiler with which the kernel was built.
-
-               Selecting 'on' will also enable the mitigation
-               against user space to user space task attacks.
-
-               Selecting 'off' will disable both the kernel and
-               the user space protections.
-
-               Specific mitigations can also be selected manually:
-
-                retpoline               auto pick between generic,lfence
-                retpoline,generic       Retpolines
-                retpoline,lfence        LFENCE; indirect branch
-                retpoline,amd           alias for retpoline,lfence
-                eibrs                   Enhanced/Auto IBRS
-                eibrs,retpoline         Enhanced/Auto IBRS + Retpolines
-                eibrs,lfence            Enhanced/Auto IBRS + LFENCE
-                ibrs                    use IBRS to protect kernel
-
-               Not specifying this option is equivalent to
-               spectre_v2=auto.
-
-               In general the kernel by default selects
-               reasonable mitigations for the current CPU. To
-               disable Spectre variant 2 mitigations, boot with
-               spectre_v2=off. Spectre variant 1 mitigations
-               cannot be disabled.
-
-       spectre_bhi=
-
-               [X86] Control mitigation of Branch History Injection
-               (BHI) vulnerability.  This setting affects the deployment
-               of the HW BHI control and the SW BHB clearing sequence.
-
-               on
-                       (default) Enable the HW or SW mitigation as
-                       needed.
-               off
-                       Disable the mitigation.
-
-For spectre_v2_user see Documentation/admin-guide/kernel-parameters.txt
+For more details on the available options, refer to Documentation/admin-guide/kernel-parameters.txt
 
 Mitigation selection guide
 --------------------------