aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorVincent Brillault <vincent.brillault@cern.ch>2018-01-08 12:39:03 +0100
committerVincent Brillault <vincent.brillault@cern.ch>2018-01-08 12:59:03 +0100
commit66f77080950dceffef6023054629a208a15220cd (patch)
treef0ab593f39e856012f116459ab18b2b48c20af8e
parent34ef5ef21b35342801a45f8f00ca43059846bad4 (diff)
downloadspectre-meltdown-checker-66f77080950dceffef6023054629a208a15220cd.tar.lz
spectre-meltdown-checker-66f77080950dceffef6023054629a208a15220cd.tar.xz
spectre-meltdown-checker-66f77080950dceffef6023054629a208a15220cd.zip
Refactor RedHat support:
- Isolate file check to different elif (allowing to add more) - Do the PTI debugfs check first (faster and supposed to be dynamic) - If pti_enable is 0, don't trust dmesg (supposed to be dynamic)
-rwxr-xr-xspectre-meltdown-checker.sh19
1 files changed, 14 insertions, 5 deletions
diff --git a/spectre-meltdown-checker.sh b/spectre-meltdown-checker.sh
index 367b3e0..f809e0d 100755
--- a/spectre-meltdown-checker.sh
+++ b/spectre-meltdown-checker.sh
@@ -171,15 +171,20 @@ if [ ! -e /sys/kernel/debug/sched_features ]; then
# try to mount the debugfs hierarchy ourselves and remember it to umount afterwards
mount -t debugfs debugfs /sys/kernel/debug 2>/dev/null && mounted_debugfs=1
fi
-if [ -e /sys/kernel/debug/ibrs_enabled -o -e /sys/kernel/debug/x86/ibrs_enabled ]; then
+if [ -e /sys/kernel/debug/ibrs_enabled ]; then
# if the file is there, we have IBRS compiled-in
pstatus green YES
ibrs_supported=1
+ ibrs_enabled=$(cat /sys/kernel/debug/ibrs_enabled 2>/dev/null)
+elif [ -e /sys/kernel/debug/x86/ibrs_enabled ]; then
+ # RedHat uses a different path (see https://access.redhat.com/articles/3311301)
+ pstatus green YES
+ ibrs_supported=1
+ ibrs_enabled=$(cat /sys/kernel/debug/x86/ibrs_enabled 2>/dev/null)
else
pstatus red NO
fi
-[ -f /sys/kernel/debug/ibrs_enabled ] && ibrs_enabled=$(cat /sys/kernel/debug/ibrs_enabled 2>/dev/null) || ibrs_enabled=$(cat /sys/kernel/debug/x86/ibrs_enabled 2>/dev/null)
/bin/echo -n "* IBRS enabled for Kernel space: "
# 0 means disabled
# 1 is enabled only for kernel space
@@ -285,13 +290,17 @@ if grep ^flags /proc/cpuinfo | grep -qw pti; then
# vanilla PTI patch sets the 'pti' flag in cpuinfo
pstatus green YES
kpti_enabled=1
+elif [ -e /sys/kernel/debug/x86/pti_enabled ]; then
+ # RedHat Backport creates a dedicated file, see https://access.redhat.com/articles/3311301
+ kpti_enabled=$(cat /sys/kernel/debug/x86/pti_enabled 2>/dev/null)
elif dmesg | grep -Eq 'Kernel/User page tables isolation: enabled|Kernel page table isolation enabled'; then
# if we can't find the flag, grep in dmesg
- pstatus green YES
kpti_enabled=1
-elif [ -e /sys/kernel/debug/x86/pti_enabled -a "$(cat /sys/kernel/debug/x86/pti_enabled 2>/dev/null)" = 1 ]; then
+else
+ kpti_enabled=0
+fi
+if [ "$kpti_enabled" = 1 ]; then
pstatus green YES
- kpti_enabled=1
else
pstatus red NO
fi