LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-14-2018, 08:14 AM   #1
Andreas7
LQ Newbie
 
Registered: May 2018
Posts: 3

Rep: Reputation: Disabled
Since mainline-kernel, presumably 4.16.7, no content in /boot/retpoline-4.16.x-xxxxx-config. Why?


Hallo together!

Sorry, i speak only bad english, better only a few words. I hope you can understand me.

Presumably since mainline-kernel 4.16.7, current 4.16.8 is in /boot/retpoline-4.16.8-041608-config no order more, what will be do retpoline agains spectre_v2 attack. The file is absolutly blank. Under mainline-kernel 4.16.6 was this not so.

My question is now, how protect the mainline-kernel 4.16.8 agains spectre_v2 with retpoline? And especially without exact order, what to do.

For the others installed kernel are the exact order for example in /boot/retpoline-4.13-xxx-config with the content:

PHP Code:
arch/x86/platform/efi/efi_stub_64..text efi_call callq *%rdi
arch
/x86/platform/efi/efi_thunk_64..text efi64_thunk callq *%rbx
arch
/x86/platform/efi/efi_thunk_64..text efi_enter32 callq *%rdi
drivers
/watchdog/hpwdt..text asminline_call callq *%r12 
I think, without exact order what should do retpoline agains a spectre_v2 attack, is retpoline in kernel senceless.

I have copy the content from /boot/retpoline-4.13-xxxx-config in /boot/retpoline_4.16.8-xxxx-config.

But I don't no, is this right so. I think yes, but I don't no. Can somebody help me perhaps?

Thank You, very much!

Andreas7
 
Old 05-15-2018, 06:58 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,311
Blog Entries: 28

Rep: Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137
What distro/version.

Your user agent icon says "Ubuntu," but that might mean one of a number of *buntus, plus you may not be using the machine you are asking about.
 
Old 05-15-2018, 08:12 PM   #3
Andreas7
LQ Newbie
 
Registered: May 2018
Posts: 3

Original Poster
Rep: Reputation: Disabled
Hi frankbell and thanks! Hi together!

The distro is kubuntu (xenial). Sorry, why do you want to knows this? What has this to do with the blank current retpoline-4.16.8-xxxxx-generic?


Bye, Andreas7
 
Old 05-23-2018, 05:06 PM   #4
Andreas7
LQ Newbie
 
Registered: May 2018
Posts: 3

Original Poster
Rep: Reputation: Disabled
Hello everybody!



I have discovered kernel 4.15 in the package sources here, as a hwe-edge package. Have then replaced the hwe package with kernel 4.13 against the package with kernel 4.15.

With kernel 4.13 there was the file retpoline .... 4.13 .....- generic with content still in / boot.
But even the kernel 4.15 installed from the Ubuntu repositories will only create an empty file in / boot retpoline-4.15 .... generic. Just as it is the case with Mainline Kernel 4.16.

At least it seems that this is normal now. But I still do not understand it. Or were the retpoline files with content about no guidance on what to do in a specter_v2 attack.

So I find that currently still very strange. Since there was more or less all the time in / boot the retpoline ... generic files with the same content. Currently, this is only the case with Kernel 4.4.

And suddenly these files are suddenly without content? Without instructions, what to do with spectre_v2 attacks? Provided, of course, /boot/retpoline....-generic were the work instructions.



Greeting Andi
 
Old 05-29-2018, 01:36 PM   #5
AwesomeMachine
LQ Guru
 
Registered: Jan 2005
Location: USA and Italy
Distribution: Debian testing/sid; OpenSuSE; Fedora; Mint
Posts: 5,524

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
retpoline is one fix for spectre. But there are others now. You can install 'spectre-meltdown-checker' and check the system for vulnerabilities.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Canonical Outs New Ubuntu Kernel Update with Compiler-Based Retpoline Mitigation LXer Syndicated Linux News 0 02-22-2018 08:42 AM
Mainline kernel boot fail with "kernel too old" hidave Slackware 4 04-22-2014 04:03 AM
Failed to boot after compiling and installing mainline linux kernel 2.6 jaydeepd Linux - Kernel 4 01-30-2014 03:16 AM
Kernel on the mainline???? linuxunix Linux - Newbie 4 08-16-2010 03:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:31 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration