diff options
| author | Pawan Gupta <[email protected]> | 2024-03-11 08:57:09 -0700 | 
|---|---|---|
| committer | Thomas Gleixner <[email protected]> | 2024-04-08 19:27:06 +0200 | 
| commit | 95a6ccbdc7199a14b71ad8901cb788ba7fb5167b (patch) | |
| tree | 2756d1354b90ff94be54ba551fbe6570365d2bf7 /tools/perf/scripts/python/gecko.py | |
| parent | ec9404e40e8f36421a2b66ecb76dc2209fe7f3ef (diff) | |
x86/bhi: Mitigate KVM by default
BHI mitigation mode spectre_bhi=auto does not deploy the software
mitigation by default. In a cloud environment, it is a likely scenario
where userspace is trusted but the guests are not trusted. Deploying
system wide mitigation in such cases is not desirable.
Update the auto mode to unconditionally mitigate against malicious
guests. Deploy the software sequence at VMexit in auto mode also, when
hardware mitigation is not available. Unlike the force =on mode,
software sequence is not deployed at syscalls in auto mode.
Suggested-by: Alexandre Chartre <[email protected]>
Signed-off-by: Pawan Gupta <[email protected]>
Signed-off-by: Daniel Sneddon <[email protected]>
Signed-off-by: Thomas Gleixner <[email protected]>
Reviewed-by: Alexandre Chartre <[email protected]>
Reviewed-by: Josh Poimboeuf <[email protected]>
Diffstat (limited to 'tools/perf/scripts/python/gecko.py')
0 files changed, 0 insertions, 0 deletions