target/i386: introduce GraniteRapids-v5 to expose ITS_NO
Expose ITS_NO by default, as users using Granite Rapids and higher CPU models would not be able to live migrate to lower CPU hosts due to missing features. In that case, they would not be vulnerable to ITS. its-no was originally added on [1], but needs to be exposed on the individual CPU models for the guests to see by default. [1] 74978391b2da ("target/i386: Make ITS_NO available to guests") Cc: Pawan Gupta <pawan.kumar.gupta@linux.intel.com> Signed-off-by: Jon Kohler <jon@nutanix.com> Link: https://lore.kernel.org/r/20251106174626.49930-4-jon@nutanix.com Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Jon Kohler committed
Nov 6, 2025 at 10:46 UTC
b40be41f37e15603059e6acd656dd335ca93f696
1 file changed
+9
target/i386/cpu.c
+9
@@ -5443,6 +5443,15 @@ static const X86CPUDefinition builtin_x86_defs[] = {
5443
{ /* end of list */ },
5444
}
5445
},
5446
+ {
5447
+ .version = 5,
5448
+ .note = "with cet-ss, cet-ibt, its-no",
5449
+ .cache_info = &xeon_gnr_cache_info,
5450
+ .props = (PropValue[]) {
5451
+ { "its-no", "on" },
5452
+ { /* end of list */ },
5453
+ }
5454
+ },
5455
{ /* end of list */ },
5456
},
5457
},