Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,7 @@ members = [
"toyos-logstream",
"toyos-manifest",
"toyos-mdns",
"toyos-microcode",
"toyos-mixer",
"toyos-net-ip",
"toyos-net-tcp",
Expand Down
18 changes: 18 additions & 0 deletions NOTICE
Original file line number Diff line number Diff line change
Expand Up @@ -394,3 +394,21 @@ a work of theirs. Two things the tools wrote are not:
machine-written metadata and a short phrase, and no licence is claimed for
it. It stays because the deleted entries and their long-name runs in front
of them are input a reader has to skip.


toyos-microcode/intel-ucode/* — Intel microcode, redistributable unmodified
---------------------------------------------------------------------------

06-8c-01 112,640 bytes, update revision 0xbe for processor signature
0x806c1, processor flags 0x80 (Tiger Lake B0/B1, the T14's
i5-1135G7)
sha256 efe83e312b90f7fe4b8f75260087edf03e048d2f4f80caef2ef631c842714bb3
06-cc-02 165,888 bytes, update revision 0x11c for processor signature
0xc06c1, processor flags 0x94, and four extended signatures
sha256 4e43bb4d23c3638f8c16967d61e8f6456ae0da2ddd1da82ab579a50715147bb1
Upstream: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files,
`intel-ucode/` at tag microcode-20260925
(commit bdc92abe5c499c3fd7988b76a128d05c9120a520), byte for byte
Licence text: licenses/Intel-microcode-license.txt (upstream's `license`,
sha256 03efb1491c7e899feb2665fa299363e64035e5444c1b8bc1f6ebed30de964e12)
SPDX-License-Identifier: LicenseRef-Intel-Microcode
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ probe is a `boot-actuators` arm or a `test-actuators` `SYS_DEBUG` action.
- `issues/kernel/user-pointer-checks-have-no-spectre-v1-fence-and-smap-is-optional.md`
- `issues/kernel/indirect-branches-and-returns-run-without-thunks.md`
- `issues/kernel/tsx-stays-as-firmware-left-it.md`
- `issues/kernel/whether-the-kernel-loads-cpu-microcode-is-the-owners.md`
- `issues/kernel/the-kernel-loads-no-cpu-microcode.md`
- `issues/kernel/no-user-address-is-drawn-per-spawn.md`
- `issues/kernel/the-kernel-has-no-stack-protector.md`
- `issues/kernel/no-kernel-address-is-drawn-per-boot.md`
Expand Down
77 changes: 77 additions & 0 deletions issues/kernel/the-kernel-loads-no-cpu-microcode.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
---
status: open
kind: defect
opened: 2026-09-29
---

# The kernel loads no CPU microcode

The kernel is to load CPU microcode signed by the CPU's maker, pinned by
version and hash the way vendor device firmware is (owner, 2026-09-30). It
loads none, so a CPU whose BIOS ships stale microcode stays below Linux at
`Ubuntu-6.8.0-142.142` on every line that rests on microcode.

**Exit**: the kernel loads current microcode early on every CPU, at least as
current as Linux's.

`toyos-microcode` validates an Intel update file and picks the update for one
CPU; nothing calls it. The T14's eight CPUs run 0xbe from its firmware, which
is Intel's newest for them at `microcode-20260925`, so a load there is a no-op.

**Where.** The kernel, on every CPU, from a file it embeds per CPU ToyOS
supports on metal. Not the loader: it runs on the BSP alone, reaching the APs
takes EFI MP Services, and the kernel reads every CPU's revision anyway. In
`percpu::init_bsp` after `idt::init` and in `percpu::init_ap` after
`control_regs::init`, before `fpu::init` on each: after the IDT, so a load that
faults reports on this kernel's channels; before anything acts on an
enumeration an update changes (CPUID.7.0:EDX, `IA32_ARCH_CAPABILITIES`, RTM
and HLE); and before `ROSTER.echo`, so `boot_aps` starting one AP at a time is
the serialisation per core that SDM Vol. 3A §12.11.6.3 asks. A CPU with
CPUID.1:ECX[31] set loads nothing, as Linux does, and `IA32_PLATFORM_ID` is
read on a GenuineIntel CPU only. The update data starts 16-byte aligned (§12.11.6),
and the trigger is an `asm!` of its own: `cpu::wrmsr` is `nomem`, and the CPU
reads the update through this write. INIT keeps an update; a hard reset clears
it (§12.11.6.1).

**Verified.** After the trigger the CPU writes 0 to `IA32_BIOS_SIGN_ID`, runs
CPUID.01H, and panics unless it reads back the update's revision (Example
12-10). After `boot_aps`, CPUs that report different revisions panic the boot.
Each CPU logs its platform, the revision it found and the one it runs. It
stops rather than run the firmware's revision behind a log line: the file is
pinned and chosen by the CPU's own signature, platform and revision, so a CPU
that does not take it means one of those is wrong, a ToyOS defect, and a boot
that went on would run below the revision its image claims with nothing red.

**AMD.** linux-firmware's `amd-ucode/microcode_amd_fam{17,19,1a}h.bin` is a
container (magic 0x00414d44): an equivalence table from CPUID.01H:EAX to a
processor ID, then patches. MSR C001_0020 takes a patch's address, and MSR 8B
must then read back its patch ID; family 0x17 also invalidates the patch's
pages (Linux `amd.c`, `__apply_microcode_amd`). On families 0x17, 0x19 and part
of 0x1a below a per-CPU cutoff revision the CPU's own signature check is broken
(EntrySign; `cpu_has_entrysign`, `need_sha_check`), so the hash pin is the only
check, as `amd_shas.c` is Linux's. linux-firmware's `LICENSE.amd-ucode` is
unread. ToyOS has no AMD metal: the nightly's EPYCs are KVM guests, which load
nothing.

**Licence.** `LicenseRef-Intel-Microcode` is in no `ALLOWED` row of
`src/licence.rs`, and a committed file ships once a shipped package's directory
holds it. So the commit that makes the kernel depend on `toyos-microcode` reds
the licence gate on both files under `toyos-microcode/intel-ucode/`, the
test-only `06-cc-02` included, whatever the kernel embeds, until an exception
scoped to CPU microcode admits them.

Each step's exit, in the testing ladder's order:

- host: the step's decisions are pure in `toyos-microcode`, each refused by
name and each red under its mutation: a hypervisor or a vendor no file
covers, `select`, a read-back that is not the update's revision, CPUs that
disagree;
- metal: a T14 boot logs platform 7 and 0xbe current on all eight CPUs; a
`boot-actuators` arm that raises only the header's revision to 0xbf and
reseals its checksum stops that boot at the read-back or at a fault, since
Intel's payload still says 0xbe;
- metal, on no machine ToyOS has: the load arm, on a CPU whose firmware runs
older microcode than the embedded file; AMD's loader, on AMD metal;
- guest: every CPU logs why it loads nothing, a hypervisor under KVM and a
vendor no file covers under TCG's `AuthenticAMD` `qemu64`, and a guest test
asserts the line.

This file was deleted.

37 changes: 37 additions & 0 deletions licenses/Intel-microcode-license.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
Copyright (c) 2018-2021 Intel Corporation.
All rights reserved.

Redistribution.

Redistribution and use in binary form, without modification, are permitted,
provided that the following conditions are met:

1. Redistributions must reproduce the above copyright notice and the
following disclaimer in the documentation and/or other materials provided
with the distribution.

2. Neither the name of Intel Corporation nor the names of its suppliers may
be used to endorse or promote products derived from this software without
specific prior written permission.

3. No reverse engineering, decompilation, or disassembly of this software
is permitted.


"Binary form" includes any format that is commonly used for electronic
conveyance that is a reversible, bit-exact translation of binary
representation to ASCII or ISO text, for example "uuencode".

DISCLAIMER.

THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
POSSIBILITY OF SUCH DAMAGE.
12 changes: 12 additions & 0 deletions src/licence.rs
Original file line number Diff line number Diff line change
Expand Up @@ -464,6 +464,18 @@ pub const COMMITTED_FILES: &[(&str, &str, &str, Terms)] = &[
"ours: a ToyOS binary this build produced (toyos-symbols/tests/real.rs)",
Terms::Spdx("MIT OR Apache-2.0"),
),
(
"toyos-microcode/intel-ucode/06-8c-01",
"efe83e312b90f7fe4b8f75260087edf03e048d2f4f80caef2ef631c842714bb3",
"NOTICE",
Terms::Spdx("LicenseRef-Intel-Microcode"),
),
(
"toyos-microcode/intel-ucode/06-cc-02",
"4e43bb4d23c3638f8c16967d61e8f6456ae0da2ddd1da82ab579a50715147bb1",
"NOTICE",
Terms::Spdx("LicenseRef-Intel-Microcode"),
),
];

/// `NOTICE` sections that name no files, and why.
Expand Down
10 changes: 10 additions & 0 deletions toyos-microcode/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# A member of the host workspace (root `Cargo.toml`):
# `no_std` so the kernel can depend on it by path, and its tests run on the host.

[package]
name = "toyos-microcode"
description = "Intel microcode update files validated and matched to a CPU as the SDM's Microcode Update Facilities define them, pure."
version = "0.1.0"
edition = "2021"
license = "MIT OR Apache-2.0"
publish = false
Binary file added toyos-microcode/intel-ucode/06-8c-01
Binary file not shown.
Binary file added toyos-microcode/intel-ucode/06-cc-02
Binary file not shown.
Loading
Loading