On Mon, 2018-10-29 at 11:17 +0100, Thomas Liske wrote: > I've patched the helper script to ignore foreign microcode updates. The > required change was in the helper shell script[1], maybe you give it a try.
Looks like the patch fixed it. FTR, this is the output with the patch: $ sudo cat /sys/devices/system/cpu/cpu0/microcode/version 0xa $ sudo sh -x /usr/lib/needrestart/iucode-scan-versions + [ = 1 ] + iucode_tool --scan-system + grep -oE [^[:space:]]+$ + sig=0x000106e5 + [ -r /sys/devices/system/cpu/cpu0/microcode/processor_flags ] + cat /sys/devices/system/cpu/cpu0/microcode/processor_flags + filter=-s 0x000106e5,0x2 + type bsdtar + IUCODE_TOOL_EXTRA_OPTIONS= + test -r /etc/default/intel-microcode + . /etc/default/intel-microcode + IUCODE_TOOL_SCANCPUS=no + IUCODE_TOOL_EXTRA_OPTIONS=-s 0x000106e5,0x13 -s 0x00020655,0x92 + test = no + [ -r /usr/share/misc/intel-microcode* ] + iucode_tool -l -s 0x000106e5,0x2 --ignore-broken -s 0x000106e5,0x13 -s 0x00020655,0x92 -tb /lib/firmware/intel-ucode + grep 0x000106e5 018/001: sig 0x000106e5, pf_mask 0x13, 2018-05-08, rev 0x000a, size 9216 -- bye, pabs https://wiki.debian.org/PaulWise
signature.asc
Description: This is a digitally signed message part