metal/devstack
Jim Somerville 2a7cb246a1 Security: Handle nospectre_v1 in the bootargs
Most of the v1 mitigation is baked into the kernel and not
optional.  The swapgs barriers are, however, optional.
They have a negative performance impact so we disable them
by using the nospectre_v1 kernel bootarg.

Partial-Bug: 1860193
Depends-On: https://review.opendev.org/#/c/705300
Signed-off-by: Jim Somerville <Jim.Somerville@windriver.com>
(cherry picked from commit 91f488af02)

Change-Id: I88c8fafe558c5f03a9d0af7c42a668decef18f5a
2020-02-03 10:28:14 -05:00
..
files Security: Handle nospectre_v1 in the bootargs 2020-02-03 10:28:14 -05:00
lib Add redfish support detection to maintenance 2019-08-19 14:03:37 +00:00
plugin.sh Followup opendev cleanup and test jobs 2019-04-22 16:42:03 +00:00
settings Followup opendev cleanup and test jobs 2019-04-22 16:42:03 +00:00