mirror of
				https://github.com/TommyTran732/Fedora-CoreOS-Ignition.git
				synced 2025-11-04 11:08:35 +01:00 
			
		
		
		
	@@ -6,12 +6,15 @@
 | 
			
		||||
    "shouldExist": [
 | 
			
		||||
      "mitigations=auto,nosmt",
 | 
			
		||||
      "spectre_v2=on",
 | 
			
		||||
      "spectre_bhi=on",
 | 
			
		||||
      "spec_store_bypass_disable=on",
 | 
			
		||||
      "tsx=off",
 | 
			
		||||
      "kvm.nx_huge_pages=force",
 | 
			
		||||
      "nosmt=force",
 | 
			
		||||
      "l1d_flush=on",
 | 
			
		||||
      "spec_rstack_overflow=safe-ret",
 | 
			
		||||
      "gather_data_sampling=force",
 | 
			
		||||
      "reg_file_data_sampling=on",
 | 
			
		||||
      "random.trust_bootloader=off",
 | 
			
		||||
      "random.trust_cpu=off",
 | 
			
		||||
      "intel_iommu=on",
 | 
			
		||||
 
 | 
			
		||||
@@ -190,12 +190,15 @@ kernel_arguments:
 | 
			
		||||
  should_exist:
 | 
			
		||||
    - mitigations=auto,nosmt
 | 
			
		||||
    - spectre_v2=on
 | 
			
		||||
    - spectre_bhi=on
 | 
			
		||||
    - spec_store_bypass_disable=on
 | 
			
		||||
    - tsx=off
 | 
			
		||||
    - kvm.nx_huge_pages=force
 | 
			
		||||
    - nosmt=force
 | 
			
		||||
    - l1d_flush=on
 | 
			
		||||
    - spec_rstack_overflow=safe-ret
 | 
			
		||||
    - gather_data_sampling=force 
 | 
			
		||||
    - reg_file_data_sampling=on
 | 
			
		||||
    - random.trust_bootloader=off
 | 
			
		||||
    - random.trust_cpu=off
 | 
			
		||||
    - intel_iommu=on
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										2
									
								
								kargs
									
									
									
									
									
								
							
							
						
						
									
										2
									
								
								kargs
									
									
									
									
									
								
							@@ -14,4 +14,4 @@
 | 
			
		||||
 | 
			
		||||
# This file is just incase you want to quickly copy-paste the kernel arguments into `rpm-ostree kargs`
 | 
			
		||||
 | 
			
		||||
mitigations=auto,nosmt spectre_v2=on spec_store_bypass_disable=on tsx=off kvm.nx_huge_pages=force nosmt=force l1d_flush=on spec_rstack_overflow=safe-ret random.trust_bootloader=off random.trust_cpu=off intel_iommu=on amd_iommu=isolation_force efi=disable_early_pci_dma iommu=force iommu.passthrough=0 iommu.strict=1 slab_nomerge init_on_alloc=1 init_on_free=1 pti=on vsyscall=none ia32_emulation=0 page_alloc.shuffle=1 randomize_kstack_offset=on debugfs=off
 | 
			
		||||
mitigations=auto,nosmt spectre_v2=on spectre_bhi=on spec_store_bypass_disable=on tsx=off kvm.nx_huge_pages=force nosmt=force l1d_flush=on spec_rstack_overflow=safe-ret gather_data_sampling=force reg_file_data_sampling=on random.trust_bootloader=off random.trust_cpu=off intel_iommu=on amd_iommu=force_isolation efi=disable_early_pci_dma iommu=force iommu.passthrough=0 iommu.strict=1 slab_nomerge init_on_alloc=1 init_on_free=1 pti=on vsyscall=none ia32_emulation=0 page_alloc.shuffle=1 randomize_kstack_offset=on debugfs=off lockdown=confidentiality module.sig_enforce=1 console=tty0 console=ttyS0,115200
 | 
			
		||||
@@ -6,12 +6,15 @@
 | 
			
		||||
    "shouldExist": [
 | 
			
		||||
      "mitigations=auto,nosmt",
 | 
			
		||||
      "spectre_v2=on",
 | 
			
		||||
      "spectre_bhi=on",
 | 
			
		||||
      "spec_store_bypass_disable=on",
 | 
			
		||||
      "tsx=off",
 | 
			
		||||
      "kvm.nx_huge_pages=force",
 | 
			
		||||
      "nosmt=force",
 | 
			
		||||
      "l1d_flush=on",
 | 
			
		||||
      "spec_rstack_overflow=safe-ret",
 | 
			
		||||
      "gather_data_sampling=force",
 | 
			
		||||
      "reg_file_data_sampling=on",
 | 
			
		||||
      "random.trust_bootloader=off",
 | 
			
		||||
      "random.trust_cpu=off",
 | 
			
		||||
      "intel_iommu=on",
 | 
			
		||||
 
 | 
			
		||||
@@ -270,12 +270,15 @@ kernel_arguments:
 | 
			
		||||
  should_exist:
 | 
			
		||||
    - mitigations=auto,nosmt
 | 
			
		||||
    - spectre_v2=on
 | 
			
		||||
    - spectre_bhi=on
 | 
			
		||||
    - spec_store_bypass_disable=on
 | 
			
		||||
    - tsx=off
 | 
			
		||||
    - kvm.nx_huge_pages=force
 | 
			
		||||
    - nosmt=force
 | 
			
		||||
    - l1d_flush=on
 | 
			
		||||
    - spec_rstack_overflow=safe-ret
 | 
			
		||||
    - gather_data_sampling=force 
 | 
			
		||||
    - reg_file_data_sampling=on
 | 
			
		||||
    - random.trust_bootloader=off
 | 
			
		||||
    - random.trust_cpu=off
 | 
			
		||||
    - intel_iommu=on
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user