Perhaps I probably should have mentioned that, but I think the array index masking approaches are going to prevail.
In many ways, spectre is one more kind of attack on code that doesn’t properly separate validating untrusted input from acting on that input, except unlike overruns and TOCTOU races, this is microarchitectural.