Gaining control of BMC from the host processor
flamingspork.com
flamingspork.com
The concern is that existing BMC firmwares have been shown as unsafe for bare-metal cloud types of configurations by default, so organisations using platforms in this environment may be doing so with false confidence.
These are silicon issues as far as I know.
FWIW the mitigation patch in OpenBMC turns off all the bridges early in u-boot to minimise the race window for system reset/AC cycles.
Obviously would be better if it was possible to avoid the race window entirely (i.e. bridges default to closed, can be strapped open by the platform designer, and opened as required by firmware). We had asked for hardware changes along these lines for future generations (but may need to push a little harder...)