metal/kickstart
Jim Somerville 0c0bffe3bc Security: Handle nospectre_v1 in the bootargs
Most of the v1 mitigation is baked into the kernel and not
optional.  The swapgs barriers are, however, optional.
They have a negative performance impact so we disable them
by using the nospectre_v1 kernel bootarg.

Partial-Bug: 1860193
Depends-On: https://review.opendev.org/#/c/705822
Signed-off-by: Jim Somerville <Jim.Somerville@windriver.com>
(cherry picked from commit 91f488af02)

Change-Id: I6a4cd2f2ce3fa949d18b0297cac73cbe3555ecb3
2020-02-04 15:29:03 -05:00
..
centos Security: Handle nospectre_v1 in the bootargs 2020-02-04 15:29:03 -05:00
LICENSE StarlingX open source release updates 2018-05-31 07:36:43 -07:00