From 91025d7129041dcbb269fc31dc6a29e69e2641d6 Mon Sep 17 00:00:00 2001 From: Mikaela Suomalainen Date: Fri, 6 Sep 2019 12:38:42 +0300 Subject: [PATCH] etc/default/grub.d: merge mds.cfg into mitigations.cfg Ref: #33 Still missing documentation/comments --- etc/default/grub.d/mds.cfg | 6 ------ etc/default/grub.d/mitigations.cfg | 7 ++++++- 2 files changed, 6 insertions(+), 7 deletions(-) delete mode 100644 etc/default/grub.d/mds.cfg diff --git a/etc/default/grub.d/mds.cfg b/etc/default/grub.d/mds.cfg deleted file mode 100644 index bcee837b..00000000 --- a/etc/default/grub.d/mds.cfg +++ /dev/null @@ -1,6 +0,0 @@ -# Enable all mitigation for Microarchitectural Data Sampling attack -# including disabling Simultaneous multithreading -# https://en.wikipedia.org/wiki/Simultaneous_multithreading -# WARNING: This may have performance impact! -# https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html -GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT mds=full,nosmt" diff --git a/etc/default/grub.d/mitigations.cfg b/etc/default/grub.d/mitigations.cfg index 3154cfcc..fe981e4a 100644 --- a/etc/default/grub.d/mitigations.cfg +++ b/etc/default/grub.d/mitigations.cfg @@ -1 +1,6 @@ -GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT mitigations=auto,nosmt" +# Enable all mitigation for Microarchitectural Data Sampling attack +# including disabling Simultaneous multithreading +# https://en.wikipedia.org/wiki/Simultaneous_multithreading +# WARNING: This may have performance impact! +# https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html +GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT l1tf=full,force mds=full,nosmt mitigations=auto,nosmt"