Description of problem:
To make things easier for management layers, we currently provide a number of variants of the pseries-rhel machine types which enable by default the Spectre & Meltdown mitigations. Specifically we have:
We don't currently have an equivalent variant for rhel 7.6.0. This is because we had been hoping that in the rhel 7.6.0 timeframe we might be able to enable the mitigations by default and dispense with the extra machine type.
Enabling the mitigations also requires updated firmware, and at this stage it's looking like that firmware (at least for POWER8) still won't be widely deployed at 7.6 release.
Therefore we probably need to keep the mitigations off by default and provide the -sxxm machine type variant to turn them on.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. Run 'qemu-kvm -machine ?'
'pseries-rhel7.5.0-sxxm' is listed, but 'pseries-rhel7.6.0-sxxm' is not.
'pseries-rhel7.6.0-sxxm' variant is listed amongst others.
Still need to confirm with IBM and PM if we want this.
Andrew Bolognani suggests consistency across RHEL7 as another argument for including the pseries-rhel7.6.0-sxxm variant, with the intention being to revisit enabling the mitigations by default in RHEL 8.0.
Updated POWER8 firmware which allows the mitigations was released on 22 May 2018 (FW860.51). It's not terribly clear how widely deployed it is yet.
We'll obviously need this new machine type for RHEL8 and qemu-kvm-ma as well.
Mirek, do we need to clone the bug for those, or do we have the same source base for the time being?
We do not need clone for qemu-kvm-ma (7.60) but we need clone for RHEL 8.
Fix included in qemu-kvm-rhev-2.12.0-8.el7
# rpm -q qemu-kvm-rhev
# /usr/libexec/qemu-kvm -M help
Supported machines are:
none empty machine
pseries-rhel7.2.0 pSeries Logical Partition (PAPR compliant)
pseries-rhel7.3.0 pSeries Logical Partition (PAPR compliant)
pseries-rhel7.3.0-sxxm pSeries Logical Partition (PAPR compliant)
pseries-rhel7.4.0 pSeries Logical Partition (PAPR compliant)
pseries-rhel7.4.0-sxxm pSeries Logical Partition (PAPR compliant)
pseries-rhel7.5.0 pSeries Logical Partition (PAPR compliant)
pseries-rhel7.5.0-sxxm pSeries Logical Partition (PAPR compliant)
pseries pSeries Logical Partition (PAPR compliant) (alias of pseries-rhel7.6.0)
pseries-rhel7.6.0 pSeries Logical Partition (PAPR compliant) (default)
pseries-rhel7.6.0-sxxm pSeries Logical Partition (PAPR compliant)
Run a round of kvm acceptance test with above qemu-kvm-rhev version with pseries-rhel7.6.0-sxxm, result is PASS.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.