mirror of
https://github.com/tommytran732/Fedora-CoreOS-Ignition
synced 2024-11-23 09:31:33 -05:00
Update kargs
Signed-off-by: Tommy <contact@tommytran.io>
This commit is contained in:
parent
e5f5980e0c
commit
4906ea33d8
@ -6,12 +6,15 @@
|
|||||||
"shouldExist": [
|
"shouldExist": [
|
||||||
"mitigations=auto,nosmt",
|
"mitigations=auto,nosmt",
|
||||||
"spectre_v2=on",
|
"spectre_v2=on",
|
||||||
|
"spectre_bhi=on",
|
||||||
"spec_store_bypass_disable=on",
|
"spec_store_bypass_disable=on",
|
||||||
"tsx=off",
|
"tsx=off",
|
||||||
"kvm.nx_huge_pages=force",
|
"kvm.nx_huge_pages=force",
|
||||||
"nosmt=force",
|
"nosmt=force",
|
||||||
"l1d_flush=on",
|
"l1d_flush=on",
|
||||||
"spec_rstack_overflow=safe-ret",
|
"spec_rstack_overflow=safe-ret",
|
||||||
|
"gather_data_sampling=force",
|
||||||
|
"reg_file_data_sampling=on",
|
||||||
"random.trust_bootloader=off",
|
"random.trust_bootloader=off",
|
||||||
"random.trust_cpu=off",
|
"random.trust_cpu=off",
|
||||||
"intel_iommu=on",
|
"intel_iommu=on",
|
||||||
|
@ -190,12 +190,15 @@ kernel_arguments:
|
|||||||
should_exist:
|
should_exist:
|
||||||
- mitigations=auto,nosmt
|
- mitigations=auto,nosmt
|
||||||
- spectre_v2=on
|
- spectre_v2=on
|
||||||
|
- spectre_bhi=on
|
||||||
- spec_store_bypass_disable=on
|
- spec_store_bypass_disable=on
|
||||||
- tsx=off
|
- tsx=off
|
||||||
- kvm.nx_huge_pages=force
|
- kvm.nx_huge_pages=force
|
||||||
- nosmt=force
|
- nosmt=force
|
||||||
- l1d_flush=on
|
- l1d_flush=on
|
||||||
- spec_rstack_overflow=safe-ret
|
- spec_rstack_overflow=safe-ret
|
||||||
|
- gather_data_sampling=force
|
||||||
|
- reg_file_data_sampling=on
|
||||||
- random.trust_bootloader=off
|
- random.trust_bootloader=off
|
||||||
- random.trust_cpu=off
|
- random.trust_cpu=off
|
||||||
- intel_iommu=on
|
- intel_iommu=on
|
||||||
|
2
kargs
2
kargs
@ -14,4 +14,4 @@
|
|||||||
|
|
||||||
# This file is just incase you want to quickly copy-paste the kernel arguments into `rpm-ostree kargs`
|
# This file is just incase you want to quickly copy-paste the kernel arguments into `rpm-ostree kargs`
|
||||||
|
|
||||||
mitigations=auto,nosmt spectre_v2=on spec_store_bypass_disable=on tsx=off kvm.nx_huge_pages=force nosmt=force l1d_flush=on spec_rstack_overflow=safe-ret random.trust_bootloader=off random.trust_cpu=off intel_iommu=on amd_iommu=isolation_force efi=disable_early_pci_dma iommu=force iommu.passthrough=0 iommu.strict=1 slab_nomerge init_on_alloc=1 init_on_free=1 pti=on vsyscall=none ia32_emulation=0 page_alloc.shuffle=1 randomize_kstack_offset=on debugfs=off
|
mitigations=auto,nosmt spectre_v2=on spectre_bhi=on spec_store_bypass_disable=on tsx=off kvm.nx_huge_pages=force nosmt=force l1d_flush=on spec_rstack_overflow=safe-ret gather_data_sampling=force reg_file_data_sampling=on random.trust_bootloader=off random.trust_cpu=off intel_iommu=on amd_iommu=force_isolation efi=disable_early_pci_dma iommu=force iommu.passthrough=0 iommu.strict=1 slab_nomerge init_on_alloc=1 init_on_free=1 pti=on vsyscall=none ia32_emulation=0 page_alloc.shuffle=1 randomize_kstack_offset=on debugfs=off lockdown=confidentiality module.sig_enforce=1 console=tty0 console=ttyS0,115200
|
@ -6,12 +6,15 @@
|
|||||||
"shouldExist": [
|
"shouldExist": [
|
||||||
"mitigations=auto,nosmt",
|
"mitigations=auto,nosmt",
|
||||||
"spectre_v2=on",
|
"spectre_v2=on",
|
||||||
|
"spectre_bhi=on",
|
||||||
"spec_store_bypass_disable=on",
|
"spec_store_bypass_disable=on",
|
||||||
"tsx=off",
|
"tsx=off",
|
||||||
"kvm.nx_huge_pages=force",
|
"kvm.nx_huge_pages=force",
|
||||||
"nosmt=force",
|
"nosmt=force",
|
||||||
"l1d_flush=on",
|
"l1d_flush=on",
|
||||||
"spec_rstack_overflow=safe-ret",
|
"spec_rstack_overflow=safe-ret",
|
||||||
|
"gather_data_sampling=force",
|
||||||
|
"reg_file_data_sampling=on",
|
||||||
"random.trust_bootloader=off",
|
"random.trust_bootloader=off",
|
||||||
"random.trust_cpu=off",
|
"random.trust_cpu=off",
|
||||||
"intel_iommu=on",
|
"intel_iommu=on",
|
||||||
|
@ -270,12 +270,15 @@ kernel_arguments:
|
|||||||
should_exist:
|
should_exist:
|
||||||
- mitigations=auto,nosmt
|
- mitigations=auto,nosmt
|
||||||
- spectre_v2=on
|
- spectre_v2=on
|
||||||
|
- spectre_bhi=on
|
||||||
- spec_store_bypass_disable=on
|
- spec_store_bypass_disable=on
|
||||||
- tsx=off
|
- tsx=off
|
||||||
- kvm.nx_huge_pages=force
|
- kvm.nx_huge_pages=force
|
||||||
- nosmt=force
|
- nosmt=force
|
||||||
- l1d_flush=on
|
- l1d_flush=on
|
||||||
- spec_rstack_overflow=safe-ret
|
- spec_rstack_overflow=safe-ret
|
||||||
|
- gather_data_sampling=force
|
||||||
|
- reg_file_data_sampling=on
|
||||||
- random.trust_bootloader=off
|
- random.trust_bootloader=off
|
||||||
- random.trust_cpu=off
|
- random.trust_cpu=off
|
||||||
- intel_iommu=on
|
- intel_iommu=on
|
||||||
|
Loading…
Reference in New Issue
Block a user