Skip to content

Conversation

raja-grewal
Copy link
Contributor

This pull request addresses a misconception with our use of mitigations=auto,nosmt. It adds documentation explaining why the kernel boot parameter is redundant and not sufficient if maximum security hardening is the goal.

See #199 (comment) for further details.

Changes

There are no changes to the functionality of the codebase.

Disabled explicitly using mitigations=auto,nosmt as it is enabled by default.

It was initially added by me in #197 based on suggestions from others inside #177 and #199.

Mandatory Checklist

  • Legal agreements accepted. By contributing to this organisation, you acknowledge you have read, understood, and agree to be bound by these these agreements:

Terms of Service, Privacy Policy, Cookie Policy, E-Sign Consent, DMCA, Imprint

Optional Checklist

The following items are optional but might be requested in certain cases.

  • I have tested it locally
  • I have reviewed and updated any documentation if relevant
  • I am providing new code and test(s) for it

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant