From: Jim Newsome <jnewsome@torproject.org>
To: aarcange@redhat.com
Cc: YiFei Zhu <zhuyifei1999@gmail.com>,
Linux Containers <containers@lists.linux-foundation.org>,
YiFei Zhu <yifeifz2@illinois.edu>, bpf <bpf@vger.kernel.org>,
kernel list <linux-kernel@vger.kernel.org>
Subject: Re: RFC: default to spec_store_bypass_disable=prctl spectre_v2_user=prctl
Date: Sat, 10 Jul 2021 13:05:46 -0500 [thread overview]
Message-ID: <55e3ba77-a305-8abb-1506-5a8aabe24bf3@torproject.org> (raw)
In-Reply-To: <20201104215702.GG24993@redhat.com>
Is anything happening with this proposal? Is there anything I could do
to help it along?
My personal motivation is that I'm involved in developing and using the
[Shadow] simulator, which we use to run hours and days long simulations.
We're currently looking into running some simulations in gitlab CI
Docker runner to take advantage of shared hardware, but Docker currently
doesn't expose a way to opt out of these mitigations without turning off
seccomp altogether [Docker FR].
I've measured these mitigations to cause simulations to take 50% longer
[Overhead], so I'm pretty motivated to find a way to disable them :).
[Shadow]: https://shadow.github.io/
[Docker FR]: https://github.com/moby/moby/issues/42619
[Overhead]:
https://github.com/shadow/shadow/issues/1489#issuecomment-871445482
P.S. Attempting to respond to a thread without actually being subscribed
to the list; sorry if this ends up not threading correctly. The CC
header was truncated so also some original recipients have been dropped.
Original thread: https://lkml.org/lkml/2020/11/4/1135
prev parent reply other threads:[~2021-07-10 18:05 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-11-04 21:57 Andrea Arcangeli
2020-11-04 22:14 ` Kees Cook
2020-11-04 23:22 ` Thomas Gleixner
2020-11-04 23:40 ` Andrea Arcangeli
2020-11-05 0:14 ` [PATCH 0/1] x86: deduplicate the spectre_v2_user documentation Andrea Arcangeli
2020-11-05 0:14 ` [PATCH 1/1] " Andrea Arcangeli
2021-09-11 21:13 ` Kees Cook
2020-11-04 23:50 ` [PATCH 1/1] x86: change default to spec_store_bypass_disable=prctl spectre_v2_user=prctl Andrea Arcangeli
2021-09-11 21:13 ` Kees Cook
2021-09-12 2:01 ` Josh Poimboeuf
2021-10-04 17:54 ` Josh Poimboeuf
2021-10-04 19:14 ` Kees Cook
2021-09-12 23:14 ` Waiman Long
2021-07-10 18:05 ` Jim Newsome [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55e3ba77-a305-8abb-1506-5a8aabe24bf3@torproject.org \
--to=jnewsome@torproject.org \
--cc=aarcange@redhat.com \
--cc=bpf@vger.kernel.org \
--cc=containers@lists.linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=yifeifz2@illinois.edu \
--cc=zhuyifei1999@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®