3
0
Fork 0
forked from mirrors/nixpkgs
nixpkgs/nixos/modules
Joachim Fasting ea4f371627
nixos/security/misc: expose SMT control option
For the hardened profile disable symmetric multi threading.  There seems to be
no *proven* method of exploiting cache sharing between threads on the same CPU
core, so this may be considered quite paranoid, considering the perf cost.
SMT can be controlled at runtime, however.  This is in keeping with OpenBSD
defaults.

TODO: since SMT is left to be controlled at runtime, changing the option
definition should take effect on system activation.  Write to
/sys/devices/system/cpu/smt/control
2018-12-27 15:00:49 +01:00
..
config config.nsswitch: load cache_oslogin and oslogin nss modules if config.security.googleOsLogin.enable is set 2018-12-21 17:52:37 +01:00
hardware Merge pull request #47297 from greydot/bladerf 2018-12-18 09:29:32 +01:00
i18n/input-method docs: format 2018-09-29 20:51:11 -04:00
installer nixos/sd-image-aarch64-new-kernel: Added to release 2018-12-26 11:03:32 +00:00
misc nixos/cockroachdb: create new service 2018-12-01 19:07:49 -06:00
profiles nixos/security/misc: expose SMT control option 2018-12-27 15:00:49 +01:00
programs Merge pull request #50596 from svanderburg/mobile-updates 2018-12-24 15:52:33 +01:00
security nixos/security/misc: expose SMT control option 2018-12-27 15:00:49 +01:00
services Merge pull request #52592 from worldofpeace/geoclue/correct-sysconf 2018-12-25 19:03:22 -05:00
system logind: make killUserProcesses an option (#51426) 2018-12-11 16:51:16 -05:00
tasks nixos: move system.autoUpgrade 2018-11-17 14:05:30 +01:00
testing Add ssh backdoor to VM tests infrastructure. 2018-09-28 10:53:08 +01:00
virtualisation nixos/modules/virtualisation/google-compute-config.nix: remove google-accounts-daemon 2018-12-21 17:52:37 +01:00
module-list.nix Merge pull request #51566 from adisbladis/google-oslogin 2018-12-24 14:11:49 +01:00
rename.nix ckb-next: move option renames to nixos/modules/rename.nix for consistency 2018-11-06 00:50:00 +00:00