metal/devstack
Jim Somerville 0c0bffe3bc Security: Handle nospectre_v1 in the bootargs
Most of the v1 mitigation is baked into the kernel and not
optional.  The swapgs barriers are, however, optional.
They have a negative performance impact so we disable them
by using the nospectre_v1 kernel bootarg.

Partial-Bug: 1860193
Depends-On: https://review.opendev.org/#/c/705822
Signed-off-by: Jim Somerville <Jim.Somerville@windriver.com>
(cherry picked from commit 91f488af02)

Change-Id: I6a4cd2f2ce3fa949d18b0297cac73cbe3555ecb3
2020-02-04 15:29:03 -05:00
..
files Security: Handle nospectre_v1 in the bootargs 2020-02-04 15:29:03 -05:00
lib Followup opendev cleanup and test jobs 2019-04-22 16:42:03 +00:00
plugin.sh Followup opendev cleanup and test jobs 2019-04-22 16:42:03 +00:00
settings Followup opendev cleanup and test jobs 2019-04-22 16:42:03 +00:00