[1] - https://bugzilla.kernel.org/show_bug.cgi?id=201685
[2] - http://lkml.iu.edu/hypermail/linux/kernel/1811.2/01328.html
[1] - https://bugzilla.kernel.org/show_bug.cgi?id=201685
[2] - http://lkml.iu.edu/hypermail/linux/kernel/1811.2/01328.html
[1] is a strange bug, because the devs have consistently been unable to reproduce it, despite constantly looking over the issue. Users of ZFS have hit problems, also, suggesting that it is not an EXT4 bug, but a very subtle problem elsewhere in the block subsystem.
[1] was, in fact, root-caused to a blk-mq bug.
As Linus remarked in the thread, the people who were paranoid about the security implications already went the BSD route and disabled SMT, while the people who don't worry about it that much suddenly get a nasty perf impact by default.
To quote an Intel rep in the thread: "Using these tools much more surgically is fine, if a paranoid task wants it for example, or when you know you are doing a hard core security transition. But always on? Yikes."
Yes, your system should default to being secure. But there's a sliding scale when deciding on security flaw mitigations of user disruption versus level of security given.
In this case, the user disruption was medium-high, and the benefits did not outweigh that, so the intersection of the two factors was refined.
If this were something every skiddy toolkit were leveraging to exfiltrate astonishing amounts of data, this might fall the other way. But right now, that's not where we are.