4 ms·
For the majority of applications that follow this guide (or need to), the OS mitigations don't matter anyways: 1. They're running only trusted code. 2. L1 cac
by steventhedev 6y ago
For the majority of applications that follow this guide (or need to), the OS mitigations don't matter anyways:
1. They're running only trusted code.
2. L1 cache attacks aren't relevant if there's only one thread ever running on a given core.
3. Kernel-bypass networking means there are no system calls in the hot path anyways, so the OS mitigations won't even run in the first place.
If you're already doing all this it may be easier/better to look at using FPGAs instead. The advantage of this approach is that you don't need to procure a card with enough LUTs to house your design, and it allows the Ops team to contribute to performance.
- toast0 6y agoIf you've reduced the number of syscalls, the mitigations almost don't matter. Turning off the mitigations is more important if you're using the kernel stack for something like a tuned HAProxy installation which is mostly syscalls.