Re: Avoid speculative indirect calls in kernel

From: Borislav Petkov
Date: Mon Jan 08 2018 - 11:22:57 EST


On Sun, Jan 07, 2018 at 11:10:38PM +0100, Willy Tarreau wrote:
> I just want to be clear that the big drop some of us are facing is
> not an option *at all* for certain processes in certain environments
> and that we'll either continue to run with pti=off or with pti=on + a
> finer grained setting ASAP.

And that's all I'm saying: do pti=off in that case. The finer-grained
"solution" is just silly.

--
Regards/Gruss,
Boris.

Good mailing practices for 400: avoid top-posting and trim the reply.