Friday, September 29, 2023

Bought a new Intel laptop? Test packages!

If you bought a new Intel laptop this year, chances are its hardware
is capable of IBT (indirect branch tracking), and OpenBSD now enables
this security feature by default.

It is very likely that some packages are broken at runtime because
they fail to handle IBT. This doesn't show up at build time, so
people need to actually run their favorite packages from a snapshot
_now_ and need to report SIGILL failures, or those problems will
not be fixed in time for the release.

--
Christian "naddy" Weisgerber naddy@mips.inka.de

No comments:

Post a Comment