[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Setting constant-time mode CPU flag



On Intel chips (Ice Lake and later) and ARM64, a bit needs to be set in
a CPU register to enforce constant-time execution.  Linux plans to set
this bit by default; Xen should do the same.  See
https://lore.kernel.org/lkml/YwgCrqutxmX0W72r@xxxxxxxxx/T/ for details.
I recommend setting the bit unconditionally and ignoring guest attempts
to change it.
-- 
Sincerely,
Demi Marie Obenour (she/her/hers)
Invisible Things Lab

Attachment: signature.asc
Description: PGP signature


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.