3 ms·
Recent Linux patches allow the scheduler to only schedule processes with the same seed on the same core. The “seed” would be something tied to the user, or some
by abotsis 5y ago
Recent Linux patches allow the scheduler to only schedule processes with the same seed on the same core. The “seed” would be something tied to the user, or something else… I don’t think they’re merged yet… but that might be a solution.
- phkahler 5y agoFrom TFA: >> We're planning to get some high core count machines to be new compute machines in our environment of general multi-user Unix login servers I think the "general multi-user Ubix login" thing assumes different users on the same CPU. Unless they're actually going to have more CPUs than users. It seems like sharing a CPU is actually less secure than sharing one via SMT because of all those SMT-specific exploits (in addition to whatever exploits might be possible due to CPU sharing).
- toast0 5y agoSharing an SMT is IMHO less secure, because the adversary can probe while the victim is running. Sharing a CPU means you can only probe the effects. It would make sense to me for a traditional multiuser shell server to have a scheduling policy prohibiting SMT sharing between users. As long as the scheduler work is not expensive, it would seem almost no-cost vs disabling SMT in case all users only run a single thread, but you can still get whatever benefits SMT provides within a user's workload.
- cozzyd 5y agoAnd... can each browser tab run as a different user? (or more likely, there's a way to have the browser opt in to some security policy that would effectively do the same thing).