On 08.02.2021 21:00, Norbert Manthey wrote:
> To prevent leaking HVM params via L1TF and similar issues on a
> hyperthread pair, let's load values of domains after performing all
> relevant checks, and blocking speculative execution.
I'd like to suggest "..., let's load values of domains only
afte
To prevent leaking HVM params via L1TF and similar issues on a
hyperthread pair, let's load values of domains after performing all
relevant checks, and blocking speculative execution.
Furthermore, speculative barriers are re-arranged to make sure we do not
allow guests running on co-located VCPUs