4 ms·
only mitigations=off is enough now. more information at https://www.kernel.org/doc/html/latest/admin-guide/kernel-parameters.html https://www.kernel.org/doc/ht
by CodeArtisan 7y ago
only mitigations=off is enough now. more information at
https://www.kernel.org/doc/html/latest/admin-guide/kernel-parameters.html https://www.kernel.org/doc/html/latest/admin-guide/kernel-pa...
search for mitigations=
- jcelerier 7y agoI let it because there were kernels with the no...=off flags but not mitigations=off yet.
- sneak 7y agoTo clarify parent comment: if you understand the security risks and wish to turn off these mitigations, on modern kernels the entirety of the linked website's kernel args can be shortened to: mitigations=off All of the rest is now redundant. TIL: the default `mitigations` value, `auto`, leaves SMT enabled—even if it's vulnerable(!!!)—to avoid surprising sysadmins who upgrade to find SMT disabled. The full protection, non-default option is: mitigations=auto,nosmt Thanks for the doc link!
- joombaga 7y ago>> the default `mitigations` value, `auto`, leaves SMT enabled—even if it's vulnerable(!!!) Is SMT always vulnerable? Is there a way to only disable SMT if it's vulnerable on the target system?
- petronio 7y agoTo my knowledge it's always vulnerable on Intel processors, but not on AMD ones due to architectural differences. The nosmt option, when added to the mitigations option, should only disable SMT on vulnerable processors according to the Linux admin guide.