Call for testers - new CPU microcode update plugins

Started by Patrick M. Hausen, July 17, 2026, 04:52:26 PM

Previous topic - Next topic
I installed the microcode-develop following the procedure in this thread. Today I installed the OPNsense 26.7.1 update. Is this enough to make it permanent or should I (de)install packages?

In the firmware - plugins is shown 1.1_1 os-cpu-microcode-intel-devel (misconfigured)
In the firmware - packages is shown cpu-microcode-intel 20260512_1, cpu-microcode-rc 1.0.2 and os-cpu-microcode-intel-devel 1.1_1

Deinstall the packages you installed manually, then install the plugin from the UI. This is to get the packages recorded as a dependency instead of directly installed.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Quote from: OPNenthu on Today at 08:21:39 AMBefore the upgrade it was updating the ucode from 0x24 to 0x26 (early).

After the upgrade it's loading late, but not actually updating the ucode.

Any error message when you invoke the script manually?

/usr/local/etc/rc.syshook.d/early/40-cpu-microcode
dmesg
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

I'm a little confused after reading this thread as I am currently running 26.1.11_10 with the os-cpu-microcode-intel v1.1 plugin and have held off updating to 26.7

To help me fully understand the current recommendation, can you please confirm that if I want to update to 26.7.1 I need to perform the following:

  • create a snapshot just in case
  • uninstall the os-cpu-microcode-intel plugin
  • update to 26.7.1
  • reinstall the os-cpu-microcode-intel plugin

One option, yes.

Second option:

- uninstall os-cpu-microcode-* plugin
- upgrade to 26.7
- update your boot loader
- imstall 26.7.1, os-cpu-microcode-*, whatever ...

The underlying issue is booting 26.7 and the plugin version that comes with it with an older boot loader. Updating the boot loader fixes that. Additionally the plugin in 26.7.1 has a workaround (which I am not entirely happy with, now that the root cause has been identified and fixed).
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Quote from: Patrick M. Hausen on Today at 10:04:45 AM
Quote from: OPNenthu on Today at 08:21:39 AMBefore the upgrade it was updating the ucode from 0x24 to 0x26 (early).

After the upgrade it's loading late, but not actually updating the ucode.

Any error message when you invoke the script manually?

/usr/local/etc/rc.syshook.d/early/40-cpu-microcode
dmesg

No, looks like a clean run.

Just doesn't report that any ucode update is applied, but clearly there should be one as per the previously installed ucode package.

root@firewall:~ # /usr/local/etc/rc.syshook.d/early/40-cpu-microcode
Updating CPU Microcode...
Done.

root@firewall:~ # dmesg
---<<BOOT>>---
Copyright (c) 1992-2025 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
    The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 15.1-RELEASE-p1 stable/26.7-n283674-12334a596709 SMP amd64
FreeBSD clang version 19.1.7 (https://github.com/llvm/llvm-project.git llvmorg-19.1.7-0-gcd708029e0b2)
[1] VT(vga): resolution 640x480
[1] CPU: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz (1996.80-MHz K8-class CPU)
[1]   Origin="GenuineIntel"  Id=0x706a8  Family=0x6  Model=0x7a  Stepping=8
[1]   Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE>
[1]   Features2=0x4ff8ebbf<SSE3,PCLMULQDQ,DTES64,MON,DS_CPL,VMX,EST,TM2,SSSE3,SDBG,CX16,xTPR,PDCM,SSE4.1,SSE4.2,x2APIC,MOVBE,POPCNT,TSCDLT,AESNI,XSAVE,OSXSAVE,RDRAND>
[1]   AMD Features=0x2c100800<SYSCALL,NX,Page1GB,RDTSCP,LM>
[1]   AMD Features2=0x101<LAHF,Prefetch>
[1]   Structured Extended Features=0x2294e287<FSGSBASE,TSCADJ,SGX,SMEP,ERMS,NFPUSG,MPX,PQE,RDSEED,SMAP,CLFLUSHOPT,PROCTRACE,SHA>
[1]   Structured Extended Features2=0x40400004<UMIP,RDPID,SGXLC>
[1]   Structured Extended Features3=0xac000400<MD_CLEAR,IBPB,STIBP,ARCH_CAP,SSBD>
[1]   XSAVE Features=0xf<XSAVEOPT,XSAVEC,XINUSE,XSAVES>
[1]   IA32_ARCH_CAPS=0x14000c6b<RDCL_NO,IBRS_ALL,SKIP_L1DFL_VME,MDS_NO>
[1]   VT-x: PAT,HLT,MTF,PAUSE,EPT,UG,VPID,VID,PostIntr
[1]   TSC: P-state invariant, performance statistics
[1] real memory  = 8589934592 (8192 MB)
[1] avail memory = 7859204096 (7495 MB)
[1] Event timer "LAPIC" quality 600
[1] ACPI APIC Table: <COREv4 COREBOOT>
[1] WARNING: L1 data cache covers fewer APIC IDs than a core (0 < 1)
[1] FreeBSD/SMP: Multiprocessor System Detected: 4 CPUs
[1] FreeBSD/SMP: 1 package(s) x 4 core(s)
[1] random: registering fast source Intel Secure Key Seed
[1] random: fast provider: "Intel Secure Key Seed"
[1] random: unblocking device.
[1] ioapic0 <Version 2.0> irqs 0-119
[1] Launching APs: 2 3 1
[1] random: entropy device external interface
[1] wlan: mac acl policy registered
[1] kbd0 at kbdmux0
[1] WARNING: Device "spkr" is Giant locked and may be deleted before FreeBSD 16.0.
[1] efirtc0: <EFI Realtime Clock>
[1] efirtc0: registered as a time-of-day clock, resolution 1.000000s
[1] smbios0: <System Management BIOS> at iomem 0x69533000-0x69533017
[1] smbios0: Entry point: v3 (64-bit), Version: 3.3
[1] aesni0: <AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS,SHA1,SHA256>
[1] acpi0: <COREv4 COREBOOT>
[1] acpi0: Power Button (fixed)
[1] hpet0: <High Precision Event Timer> iomem 0xfed00000-0xfed003ff on acpi0
[1] Timecounter "HPET" frequency 19200000 Hz quality 950
[1] Event timer "HPET" frequency 19200000 Hz quality 550
[1] Event timer "HPET1" frequency 19200000 Hz quality 440
[1] Event timer "HPET2" frequency 19200000 Hz quality 440
[1] Event timer "HPET3" frequency 19200000 Hz quality 440
[1] Event timer "HPET4" frequency 19200000 Hz quality 440
[1] atrtc0: <AT realtime clock> port 0x70-0x77 on acpi0
[1] atrtc0: registered as a time-of-day clock, resolution 1.000000s
[1] Event timer "RTC" frequency 32768 Hz quality 0
[1] attimer0: <AT timer> port 0x40-0x43,0x50-0x53 irq 0 on acpi0
[1] Timecounter "i8254" frequency 1193182 Hz quality 0
[1] Event timer "i8254" frequency 1193182 Hz quality 100
[1] Timecounter "ACPI-fast" frequency 3579545 Hz quality 900
[1] acpi_timer0: <24-bit timer at 3.579545MHz> port 0x408-0x40b on acpi0
[1] pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
[1] pci0: <ACPI PCI bus> on pcib0
[1] vgapci0: <VGA-compatible display> port 0x5000-0x503f mem 0x90000000-0x90ffffff,0x80000000-0x8fffffff at device 2.0 on pci0
[1] vgapci0: Boot video device
[1] hdac0: <Intel Gemini Lake HDA Controller> mem 0x91510000-0x91513fff,0x91000000-0x910fffff at device 14.0 on pci0
[1] pci0: <simple comms> at device 15.0 (no driver attached)
[1] ahci0: <Intel Gemini Lake AHCI SATA controller> port 0x5060-0x5067,0x5068-0x506b,0x5040-0x505f mem 0x91514000-0x91515fff,0x9151c000-0x9151c0ff,0x9151b000-0x9151b7ff at device 18.0 on pci0
[1] ahci0: AHCI v1.31 with 2 6Gbps ports, Port Multiplier supported
[1] ahcich0: <AHCI channel> at channel 0 on ahci0
[1] ahcich1: <AHCI channel> at channel 1 on ahci0
[1] pcib1: <ACPI PCI-PCI bridge> at device 19.0 on pci0
[1] pci1: <ACPI PCI bus> on pcib1
[1] igb0: <Intel(R) I210 Flashless (Copper)> port 0x1000-0x101f mem 0x91100000-0x9111ffff,0x91120000-0x91123fff at device 0.0 on pci1
[1] igb0: NVM V0.6 imgtype6
[1] igb0: Using 1024 TX descriptors and 1024 RX descriptors
[1] igb0: Using 4 RX queues 4 TX queues
[1] igb0: Using MSI-X interrupts with 5 vectors
[1] igb0: Ethernet address: <redacted>
[1] igb0: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib2: <PCI-PCI bridge> at device 19.1 on pci0
[1] pci2: <PCI bus> on pcib2
[1] igb1: <Intel(R) I210 Flashless (Copper)> port 0x2000-0x201f mem 0x91200000-0x9121ffff,0x91220000-0x91223fff at device 0.0 on pci2
[1] igb1: NVM V0.6 imgtype6
[1] igb1: Using 1024 TX descriptors and 1024 RX descriptors
[1] igb1: Using 4 RX queues 4 TX queues
[1] igb1: Using MSI-X interrupts with 5 vectors
[1] igb1: Ethernet address: <redacted>
[1] igb1: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib3: <PCI-PCI bridge> at device 19.2 on pci0
[1] pci3: <PCI bus> on pcib3
[1] igb2: <Intel(R) I210 Flashless (Copper)> port 0x3000-0x301f mem 0x91300000-0x9131ffff,0x91320000-0x91323fff at device 0.0 on pci3
[1] igb2: NVM V0.6 imgtype6
[1] igb2: Using 1024 TX descriptors and 1024 RX descriptors
[1] igb2: Using 4 RX queues 4 TX queues
[1] igb2: Using MSI-X interrupts with 5 vectors
[1] igb2: Ethernet address: <redacted>
[1] igb2: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib4: <PCI-PCI bridge> at device 19.3 on pci0
[1] pci4: <PCI bus> on pcib4
[1] pcib5: <PCI-PCI bridge> at device 0.0 on pci4
[1] pci5: <PCI bus> on pcib5
[1] pcib6: <PCI-PCI bridge> at device 1.0 on pci5
[1] pci6: <PCI bus> on pcib6
[1] igb3: <Intel(R) I210 Flashless (Copper)> port 0x4000-0x401f mem 0x91400000-0x9141ffff,0x91420000-0x91423fff at device 0.0 on pci6
[1] igb3: NVM V0.6 imgtype6
[1] igb3: Using 1024 TX descriptors and 1024 RX descriptors
[1] igb3: Using 4 RX queues 4 TX queues
[1] igb3: Using MSI-X interrupts with 5 vectors
[1] igb3: Ethernet address: <redacted>
[1] igb3: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib7: <PCI-PCI bridge> at device 3.0 on pci5
[1] pci7: <PCI bus> on pcib7
[1] pcib8: <PCI-PCI bridge> at device 5.0 on pci5
[1] pci8: <PCI bus> on pcib8
[1] pcib9: <PCI-PCI bridge> at device 7.0 on pci5
[1] pci9: <PCI bus> on pcib9
[1] xhci0: <Intel Gemini Lake USB 3.0 controller> mem 0x91500000-0x9150ffff at device 21.0 on pci0
[1] xhci0: 32 bytes context size, 64-bit DMA
[1] xhci0: xECP capabilities <PROTO,PROTO,VEND(c0),LEGACY,VEND(c6),VEND(c7),VEND(c2),DEBUG,VEND(c3),VEND(c4),VEND(c5),VEND(c8),VEND(c9),VEND(cb)>
[1] usbus0 on xhci0
[1] usbus0: 5.0Gbps Super Speed USB v3.0
[1] sdhci_pci0: <Generic SD HCI> mem 0x91519000-0x91519fff,0x9151a000-0x9151afff at device 28.0 on pci0
[1] sdhci_pci0: 1 slot(s) allocated
[1] mmc0: <MMC/SD bus> on sdhci_pci0
[1] isab0: <PCI-ISA bridge> at device 31.0 on pci0
[1] isa0: <ISA bus> on isab0
[1] acpi_button0: <Sleep Button> on acpi0
[1] cpu0: <ACPI CPU> on acpi0
[1] uart: ns8250: UART FCR is broken (0x1)
[1] uart0: <16550 or compatible> at port 0x3f8 irq 4 flags 0x10 on isa0
[1] uart0: console (115200,n,8,1)
[1] est0: <Enhanced SpeedStep Frequency Control> on cpu0
[1] cpufreq0: <CPU frequency control> on cpu0
[1] cpufreq1: <CPU frequency control> on cpu1
[1] cpufreq2: <CPU frequency control> on cpu2
[1] cpufreq3: <CPU frequency control> on cpu3
[1] Timecounter "TSC" frequency 1996800733 Hz quality 1000
[1] Timecounters tick every 1.000 msec
[1] ugen0.1: <Intel XHCI root HUB> at usbus0
[1] uhub0 on usbus0
[1] uhub0: <Intel XHCI root HUB, class 9/0, rev 3.00/1.00, addr 1> on usbus0
[1] ZFS filesystem version: 5
[1] ZFS storage pool version: features support (5000)
[1] hdacc0: <Intel Gemini Lake HDA CODEC> at cad 2 on hdac0
[1] hdaa0: <Intel Gemini Lake Audio Function Group> at nid 1 on hdacc0
[1] pcm0: <Intel Gemini Lake (HDMI/DP 8ch)> at nid 3 on hdaa0
[1] mmcsd0: 8GB <MMCHC 8GTF4R 0.6 SN 115AE8FD MFG 02/2023 by 21 0x0000> at mmc0 200.0MHz/8bit/8192-block
[1] mmcsd0boot0: 4MB partition 1 at mmcsd0
[1] mmcsd0boot1: 4MB partition 2 at mmcsd0
[1] mmcsd0rpmb: 524kB partition 3 at mmcsd0
[1] ada0 at ahcich0 bus 0 scbus0 target 0 lun 0
ada0: <CT1000MX500SSD4 M3CR023> ACS-3 ATA SATA 3.x device
ada0: Serial Number 1826E146E7D3
ada0: 600.000MB/s transfers (SATA 3.x, UDMA6, PIO 512bytes)
ada0: Command Queueing enabled
ada0: 953869MB (1953525168 512 byte sectors)
[1] Trying to mount root from zfs:zroot/ROOT/default []...
[2] uhub0: 16 ports with 16 removable, self powered
[2] Dual Console: Serial Primary, Video Secondary
[10] CPU: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz (1996.80-MHz K8-class CPU)
[10]   Origin="GenuineIntel"  Id=0x706a8  Family=0x6  Model=0x7a  Stepping=8
[10]   Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE>
[10]   Features2=0x4ff8ebbf<SSE3,PCLMULQDQ,DTES64,MON,DS_CPL,VMX,EST,TM2,SSSE3,SDBG,CX16,xTPR,PDCM,SSE4.1,SSE4.2,x2APIC,MOVBE,POPCNT,TSCDLT,AESNI,XSAVE,OSXSAVE,RDRAND>
[10]   AMD Features=0x2c100800<SYSCALL,NX,Page1GB,RDTSCP,LM>
[10]   AMD Features2=0x101<LAHF,Prefetch>
[10]   Structured Extended Features=0x2294e287<FSGSBASE,TSCADJ,SGX,SMEP,ERMS,NFPUSG,MPX,PQE,RDSEED,SMAP,CLFLUSHOPT,PROCTRACE,SHA>
[10]   Structured Extended Features2=0x40400004<UMIP,RDPID,SGXLC>
[10]   Structured Extended Features3=0xac000400<MD_CLEAR,IBPB,STIBP,ARCH_CAP,SSBD>
[10]   XSAVE Features=0xf<XSAVEOPT,XSAVEC,XINUSE,XSAVES>
[10]   IA32_ARCH_CAPS=0x14000c6b<RDCL_NO,IBRS_ALL,SKIP_L1DFL_VME,MDS_NO>
[10]   VT-x: PAT,HLT,MTF,PAUSE,EPT,UG,VPID,VID,PostIntr
[10]   TSC: P-state invariant, performance statistics
[12] igb0: link state changed to UP
[13] igb1: link state changed to UP
[14] igb2: link state changed to UP
[20] ichsmb0: <Intel Gemini Lake SMBus controller> port 0xefa0-0xefbf mem 0x9151d000-0x9151d0ff at device 31.1 on pci0
[20] smbus0: <System Management Bus> on ichsmb0
[22] lo0: link state changed to UP
[22] coretemp0: <CPU On-Die Thermal Sensors> on cpu0
[25] load_dn_sched dn_sched FIFO loaded
[25] load_dn_sched dn_sched QFQ loaded
[25] load_dn_sched dn_sched RR loaded
[25] load_dn_sched dn_sched WF2Q+ loaded
[25] load_dn_sched dn_sched PRIO loaded
[25] load_dn_sched dn_sched FQ_CODEL loaded
[25] load_dn_sched dn_sched FQ_PIE loaded
[25] load_dn_aqm dn_aqm CODEL loaded
[25] load_dn_aqm dn_aqm PIE loaded
[25] ipfw2 (+ipv6) initialized, divert loadable, nat loadable, default to accept, logging disabled
[28] vlan0: changing name to 'vlan0.2010'
[28] igb2: link state changed to DOWN
[28] vlan1: changing name to 'vlan0.2020'
[28] vlan2: changing name to 'vlan0.2030'
[28] vlan3: changing name to 'vlan0.2040'
[28] vlan4: changing name to 'vlan0.2050'
[28] vlan5: changing name to 'vlan0.2060'
[28] vlan6: changing name to 'vlan0.2070'
[30] igb0: link state changed to DOWN
[32] igb2: link state changed to UP
[32] vlan0.2040: link state changed to UP
[32] vlan0.2010: link state changed to UP
[32] vlan0.2060: link state changed to UP
[32] vlan0.2030: link state changed to UP
[32] vlan0.2050: link state changed to UP
[32] vlan0.2020: link state changed to UP
[32] vlan0.2070: link state changed to UP
[32] igb1: link state changed to DOWN
[34] igb0: link state changed to UP
[36] igb1: link state changed to UP
[43] wg0: link state changed to UP
[6299] CPU: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz (1996.80-MHz K8-class CPU)
[6299]   Origin="GenuineIntel"  Id=0x706a8  Family=0x6  Model=0x7a  Stepping=8
[6299]   Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE>
[6299]   Features2=0x4ff8ebbf<SSE3,PCLMULQDQ,DTES64,MON,DS_CPL,VMX,EST,TM2,SSSE3,SDBG,CX16,xTPR,PDCM,SSE4.1,SSE4.2,x2APIC,MOVBE,POPCNT,TSCDLT,AESNI,XSAVE,OSXSAVE,RDRAND>
[6299]   AMD Features=0x2c100800<SYSCALL,NX,Page1GB,RDTSCP,LM>
[6299]   AMD Features2=0x101<LAHF,Prefetch>
[6299]   Structured Extended Features=0x2294e287<FSGSBASE,TSCADJ,SGX,SMEP,ERMS,NFPUSG,MPX,PQE,RDSEED,SMAP,CLFLUSHOPT,PROCTRACE,SHA>
[6299]   Structured Extended Features2=0x40400004<UMIP,RDPID,SGXLC>
[6299]   Structured Extended Features3=0xac000400<MD_CLEAR,IBPB,STIBP,ARCH_CAP,SSBD>
[6299]   XSAVE Features=0xf<XSAVEOPT,XSAVEC,XINUSE,XSAVES>
[6299]   IA32_ARCH_CAPS=0x14000c6b<RDCL_NO,IBRS_ALL,SKIP_L1DFL_VME,MDS_NO>
[6299]   VT-x: PAT,HLT,MTF,PAUSE,EPT,UG,VPID,VID,PostIntr
[6299]   TSC: P-state invariant, performance statistics
N5105 | 8/250GB | 4xi226-V | Community

Thank you Patrick,

Re your second option, if the three files /boot/loader.efi /boot/efi/efi/boot/bootx64.efi /boot/efi/efi/freebsd/loader.efi are identical in size, can I assume there's no need to update the boot loader?

With the updated boot loader in place you can enable early loading if you like. Add two tunables following

https://github.com/opnsense/plugins/blob/ac68d4ef08fbd7aed966f41daec3c443673dc533/sysutils/cpu-microcode/src/etc/rc.loader.d/40-cpu-microcode.in
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Quote from: vk2him on Today at 10:34:35 AMThank you Patrick,

Re your second option, if the three files /boot/loader.efi /boot/efi/efi/boot/bootx64.efi /boot/efi/efi/freebsd/loader.efi are identical in size, can I assume there's no need to update the boot loader?

Are they AFTER you upgraded to 26.7? I doubt that. You need to update the boot loader with the version that comes with FreeBSD 15.1 which is only present as /boot/loader.efi after the upgrade.

Second size doesn't say anything about the content. Try "cmp" to check if the files are identical. Or simply copy /boot/loader.efi over the two other ones - won't hurt.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Today at 10:52:15 AM #69 Last Edit: Today at 10:54:45 AM by OPNenthu
@Patrick, I got this command from ChatGPT.  It looks like the loaded ucode is 0x26, which is the updated version.  So the late loading is working even though it doesn't print anything was applied in dmesg.

Maybe it's simply a logging bug then and not a functional one.

root@firewall:~ # cpucontrol -m 0x8b /dev/cpuctl0
MSR 0x8b: 0x00000026 0x00000000

JFYI
N5105 | 8/250GB | 4xi226-V | Community