pti=off spectre_v2=off l1tf=off nospec_store_bypass_disable no_stf_barrier
Would it make sense to have a single flag to "run insecure but fast" that we can use on pure development machines, test servers and the like? My Intel development server only runs code I choose.1. Development machines should be configured identically to production machines. (Do you install a GUI and development tools on your production servers?) Occasional differences in behavior between development/production are par for the course, and is why staging environments are commonly used.
2. The mitigations affect the execution result of code likely to be developed/executed at a typical software shop. AFAIU the attacks are timing-based, and won't affect valid code that's not specifically looking to exploit them.
Pretty much any application where there is limited execution time budget. If it takes too long it's considered broken, unusable, undesirable etc. Any realtime-ish stuff.
Ad bidding, video processing, audio processing / messaging, industrial control systems, robotics, general signal processing, logging systems that will now be overwhelmed and drop messages, databases that will experience timeouts and retries, scientific computations that will now take weeks more to run and potentially screw up other projects.
But hey it's a great time for Intel. Hey, psst, over here, I got a faster later gen CPU for you, for an easy price of $999.99 to bring you performance back to where it was last week.
https://github.com/torvalds/linux/blob/master/Documentation/...
modinfo ${somemodule}
man lsmod man modinfo
This is elementary level linux, you should know this.
Also the kernel flags, don't block intel microcode "improvements". You have to do this with:
sudo apt-mark hold intel-microcode
and look for what's currently installed.Mitigation isn't a fix, it's a bandaid.