Repository navigation
Force enable PTI on ARM64 CPUs - #333
Conversation
|
I'm slightly confused why the README now states that page table isolation is only enabled on x86_64 CPUs when we're also adding an option that enables it on arm64 CPUs? If there aren't any objections, I'll revert that part when I merge this into my arraybolt3/trixie branch. I'm also wondering if maybe In the event we start running out of kernel command line space, we might want to think about making some parameters arch-dependent, like |
|
Merged, but added a mention of arm64 CPUs to the README rather than removing the x86_64 mention. Ultimately the whole bit about PTI probably needs to move out of the "kernel space" section, but this will make it less confusing for the time being until we move that section. |
This pull request force enables PTI of user and kernel address spaces on ARM64 CPUs mitigating the Meltdown vulnerability.
This was previously missed as the already used
pti=onparameter only applies to X86_64 CPUs. See the kernel docs for details.In various other areas documentation has been approved making the applicability to different architectures clearer.
Changes
Set the
kpti=1kernel boot parameter.Update documentation in other areas relating to ARM64.
Mandatory Checklist
Terms of Service, Privacy Policy, Cookie Policy, E-Sign Consent, DMCA, Imprint
Optional Checklist
The following items are optional but might be requested in certain cases.