Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

profiles: add CFLAGS to prevent the Spectre v2 #28

Merged
merged 1 commit into from Apr 27, 2019

Conversation

Projects
None yet
1 participant
@dongsupark
Copy link
Contributor

commented Apr 27, 2019

To be able to prevent the Spectre v2, we should add the following CFLAGS -mindirect-branch=thunk and -mindirect-branch-register for the general profile.

See also:
https://security.googleblog.com/2018/01/more-details-about-mitigations-for-cpu_4.html
https://groups.google.com/forum/#!topic/linux.gentoo.user/6xUuPccmxtU

profiles: add CFLAGS to prevent the Spectre v2
To be able to prevent the Spectre v2, we should add the following CFLAGS
`-mindirect-branch=thunk` and `-mindirect-branch-register` for the
general profile.

See also:
https://security.googleblog.com/2018/01/more-details-about-mitigations-for-cpu_4.html
https://groups.google.com/forum/#!topic/linux.gentoo.user/6xUuPccmxtU

@dongsupark dongsupark merged commit 0f2ad9f into flatcar-master-edge Apr 27, 2019

@dongsupark dongsupark deleted the dongsu/cflags branch Apr 27, 2019

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.