Advice on spectre/meltdown and how to mitigate performance impacts
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Security Notes |
New
|
Undecided
|
Unassigned |
Bug Description
This bug is the result of discussions by the Security SIG. High level overview is here https:/
A few questions to answer:
1) What is the scope of this documentation activity? Does it include all Spectre and Meltdown vulnerabilities? As far as I can tell out of the eight spectre-ng (https:/
https:/
https:/
2) What is the status of mitigations in OpenStack? CPU manufacturers have not yet completed all remediation, so I believe it is not possible for performance mitigations in OpenStack to be complete. These patches are related (https:/
3) Can we offer any advice to operators on how to prepare for potential future discoveries in this space?