Flawed use of mitigations=auto,nosmt
#320
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This pull request addresses a misconception with our use of
mitigations=auto,nosmt
. It adds documentation explaining why the kernel boot parameter is redundant and not sufficient if maximum security hardening is the goal.See #199 (comment) for further details.
Changes
There are no changes to the functionality of the codebase.
Disabled explicitly using
mitigations=auto,nosmt
as it is enabled by default.It was initially added by me in #197 based on suggestions from others inside #177 and #199.
Mandatory Checklist
Terms of Service, Privacy Policy, Cookie Policy, E-Sign Consent, DMCA, Imprint
Optional Checklist
The following items are optional but might be requested in certain cases.