Commit a5085a0d by Alexander Popov

Add kernel command line options enabling mitigations of side-channel attacks

parent 8289cd8c
...@@ -17,6 +17,12 @@ ...@@ -17,6 +17,12 @@
# kernel.kptr_restrict=1 # kernel.kptr_restrict=1
# lockdown=1 # lockdown=1
# #
# spectre_v2=on
# pti=on
# spec_store_bypass_disable=on
# l1tf=full,force
#
#
# N.B. Hardening sysctl's: # N.B. Hardening sysctl's:
# net.core.bpf_jit_harden # net.core.bpf_jit_harden
# #
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment