On Sat, 13 Jan 2018, Paul Wise wrote:
> It should be enough, but it would be better to handle all cases IMO.
> I have no idea if iucode-tool handles systems with multiple sockets,
> so I am CCing Debian's Intel/AMD microcode maintainer.

Current versions of iucode_tool will include microcode for every
stepping of whatever processor it detects using cpuid.

This errs in the side of caution (it may include more steppings than
strictly required), because the allowed-stepping-mixing rules vary with
processor model(!).

> > For the check in needrestart it should be enough to compare the current
> > running microcode signature with the latest available one. This would
> > also handle outdated initrd images gracefuly.
> 
> I think on Debian at least, outdated microcode in the initrd could only
> be intentional on the part of the sysadmin.

Who knows... people do strange things.

-- 
  Henrique Holschuh

Reply via email to