Skip to content

Flawed use of mitigations=auto,nosmt - #320

Merged
adrelanos merged 5 commits into
Kicksecure:masterfrom
raja-grewal:incomplete_cpu_mitigations
Dec 19, 2025
Merged

adrelanos merged 5 commits into
Kicksecure:masterfrom
raja-grewal:incomplete_cpu_mitigations

Conversation

@raja-grewal

Copy link
Copy Markdown
Contributor

This pull request addresses a misconception with our use of mitigations=auto,nosmt. It adds documentation explaining why the kernel boot parameter is redundant and not sufficient if maximum security hardening is the goal.

See #199 (comment) for further details.

Changes

There are no changes to the functionality of the codebase.

Disabled explicitly using mitigations=auto,nosmt as it is enabled by default.

It was initially added by me in #197 based on suggestions from others inside #177 and #199.

Mandatory Checklist

  • Legal agreements accepted. By contributing to this organisation, you acknowledge you have read, understood, and agree to be bound by these these agreements:

Terms of Service, Privacy Policy, Cookie Policy, E-Sign Consent, DMCA, Imprint

Optional Checklist

The following items are optional but might be requested in certain cases.

  • I have tested it locally
  • I have reviewed and updated any documentation if relevant
  • I am providing new code and test(s) for it

@ArrayBolt3 ArrayBolt3 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Merged into my arraybolt3/trixie branch, thank you!

@adrelanos
adrelanos merged commit e7e6d6d into Kicksecure:master Dec 19, 2025
@raja-grewal
raja-grewal deleted the incomplete_cpu_mitigations branch December 19, 2025 23:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants