security-misc/etc
Patrick Schleizer b9d65338bc
unconditionally enable all CPU bugs (spectre, meltdown, L1TF, ...)
this might reduce performance

* `spectre_v2=on`
* `spec_store_bypass_disable=on`
* `tsx=off`
* `tsx_async_abort=full,nosmt`

Thanks to @madaidan for the suggestion!

https://forums.whonix.org/t/should-all-kernel-patches-for-cpu-bugs-be-unconditionally-enabled-vs-performance-vs-applicability/7647
2020-01-30 05:55:13 -05:00
..
apparmor.d/tunables/home.d Delete usr.lib.security-misc.pam_tally2-info 2019-12-20 22:44:31 +00:00
apt/apt.conf.d Enable APT seccomp sandboxing. 2019-07-07 09:37:25 +00:00
default/grub.d unconditionally enable all CPU bugs (spectre, meltdown, L1TF, ...) 2020-01-30 05:55:13 -05:00
hide-hardware-info.d copyright 2019-10-31 11:19:44 -04:00
initramfs-tools error handling 2020-01-15 15:54:06 -05:00
kernel/postinst.d add hook etc/kernel/postinst.d/30_remove-system-map to remove system.map 2019-08-14 07:22:14 +00:00
modprobe.d merge the many modprobe.d config files into 1 2020-01-24 04:30:36 -05:00
permission-hardening.d Protect /bin/mount from 'chmod -x'. 2019-12-30 06:39:24 -05:00
security add digits to drop-in file names 2020-01-24 04:39:06 -05:00
skel/.config/xfce4/xfconf/xfce-perchannel-xml solve package file conflict 2019-06-09 10:06:58 +00:00
sudoers.d fix xfce4-power-manager xfpm-power-backlight-helper pkexec lxsudo popup 2020-01-15 02:42:10 -05:00
sysctl.d merge the many sysctl config files into 1 2020-01-24 04:26:36 -05:00
systemd/system fix path 2019-07-17 21:02:48 +00:00
thunderbird/pref Enables punycode (network.IDN_show_punycode) by default in Thunderbird 2019-11-03 02:50:51 -05:00
X11/Xsession.d copyright 2019-10-31 11:19:44 -04:00
securetty.security-misc Don't allow root login from a terminal 2019-07-08 23:17:17 +00:00