diff --git a/etc/default/grub.d/mds.cfg b/etc/default/grub.d/mds.cfg deleted file mode 100644 index bcee837b..00000000 --- a/etc/default/grub.d/mds.cfg +++ /dev/null @@ -1,6 +0,0 @@ -# Enable all mitigation for Microarchitectural Data Sampling attack -# including disabling Simultaneous multithreading -# https://en.wikipedia.org/wiki/Simultaneous_multithreading -# WARNING: This may have performance impact! -# https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html -GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT mds=full,nosmt" diff --git a/etc/default/grub.d/mitigations.cfg b/etc/default/grub.d/mitigations.cfg index 3154cfcc..fe981e4a 100644 --- a/etc/default/grub.d/mitigations.cfg +++ b/etc/default/grub.d/mitigations.cfg @@ -1 +1,6 @@ -GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT mitigations=auto,nosmt" +# Enable all mitigation for Microarchitectural Data Sampling attack +# including disabling Simultaneous multithreading +# https://en.wikipedia.org/wiki/Simultaneous_multithreading +# WARNING: This may have performance impact! +# https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html +GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT l1tf=full,force mds=full,nosmt mitigations=auto,nosmt"