From mboxrd@z Thu Jan 1 00:00:00 1970 From: Adonay Felipe Nogueira Subject: Re: Meltdown / Spectre Date: Wed, 10 Jan 2018 09:49:54 -0200 Message-ID: <87efmy9bml.fsf@hyperbola.info> References: <874lnzcedp.fsf@gmail.com> <20180106174358.GA28436@jasmine.lan> <87lghapeu5.fsf@gmail.com> <87incc6z9o.fsf@gmail.com> <87fu7g436e.fsf@fastmail.com> <87vagad3xx.fsf@netris.org> <87tvvukqct.fsf@gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:41334) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eZEtQ-0003ew-P3 for guix-devel@gnu.org; Wed, 10 Jan 2018 06:50:06 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1eZEtN-0000l2-Nx for guix-devel@gnu.org; Wed, 10 Jan 2018 06:50:04 -0500 Received: from relay6-d.mail.gandi.net ([217.70.183.198]:59758) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1eZEtN-0000k0-Fb for guix-devel@gnu.org; Wed, 10 Jan 2018 06:50:01 -0500 Received: from adfeno-pc1 (unknown [181.221.151.169]) (Authenticated sender: adfeno@hyperbola.info) by relay6-d.mail.gandi.net (Postfix) with ESMTPSA id 0B422FB8D4 for ; Wed, 10 Jan 2018 12:49:58 +0100 (CET) In-Reply-To: <87tvvukqct.fsf@gmail.com> (Chris Marusich's message of "Wed, 10 Jan 2018 01:36:18 -0800") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org I don't know if this serves as guidance as to if microcode is functional or not, but from [1] I quote: #+BEGIN_QUOTE However, there is an exception for secondary embedded processors. The exception applies to software delivered inside auxiliary and low-level processors and FPGAs, within which software installation is not intended after the user obtains the product. This can include, for instance, microcode inside a processor, firmware built into an I/O device, or the gate pattern of an FPGA. The software in such secondary processors does not count as product software. #+END_QUOTE My (perhaps uninformed) opinion is that it's functional data, but not the sort of "functional" that every human would be allowed to modify after it was first written. [1] . 2018-01-10T01:36:18-0800 Chris Marusich wrote: > According to the user named _4of7 in the #libreboot channel of the > Freenode IRC network, the email list development@libreboot.org is down. > So the Libreboot maintainers have probably not seen this email thread. > > According to _4of7, currently the best way to contact the Libreboot > maintainers is IRC. It would probably be best to ask there. If you get > a response, please don't forget to update us here on this thread! > > When I asked in #freenode today, _4of7 responded as follows: > > <_4of7> There's not much we can do from the Libreboot side, but there a= re > <_4of7> mitigations on kernel side... since it's exploitable from javas= cript > <_4of7> you could also e.g. not run JavaScript. specing on #libreboot I= RC had > <_4of7> the idea to run Firefox without the JIT enabled - we both tried= to > <_4of7> compile the latest ESR however, with --disable-ion, and it segf= aulted. > <_4of7> I tried to build ff 45esr instead, but that build failed. > > I'm not sure who _4of7 is, so I don't know if they speak for the > Libreboot project. > > > Does the GNU Project have a policy regarding this sort of thing? I > wasn't able to find any articles on gnu.org that discuss it. > > If no such policy exists, then should this topic be discussed somewhere > like gnu-system-discuss@gnu.org? I don't know where discussions like > this normally take place within the GNU project. It's definitely a > discussion worth having, though. --=20 - https://libreplanet.org/wiki/User:Adfeno - Palestrante e consultor sobre /software/ livre (n=C3=A3o confundir com gratis). - "WhatsApp"? Ele n=C3=A3o =C3=A9 livre. Por favor, veja formas de se comun= icar instantaneamente comigo no endere=C3=A7o abaixo. - Contato: https://libreplanet.org/wiki/User:Adfeno#vCard - Arquivos comuns aceitos (apenas sem DRM): Corel Draw, Microsoft Office, MP3, MP4, WMA, WMV. - Arquivos comuns aceitos e enviados: CSV, GNU Dia, GNU Emacs Org, GNU GIMP, Inkscape SVG, JPG, LibreOffice (padr=C3=A3o ODF), OGG, OPUS, PDF (apenas sem DRM), PNG, TXT, WEBM.