<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: More Meltdown fixes	</title>
	<atom:link href="https://www.dragonflydigest.com/2018/01/08/more-meltdown-fixes/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dragonflydigest.com/2018/01/08/more-meltdown-fixes/</link>
	<description>A running description of activity related to DragonFly BSD.</description>
	<lastBuildDate>Thu, 11 Jan 2018 02:29:05 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>
	<item>
		<title>
		By: Sepherosa Ziehau		</title>
		<link>https://www.dragonflydigest.com/2018/01/08/more-meltdown-fixes/comment-page-1/#comment-487116</link>

		<dc:creator><![CDATA[Sepherosa Ziehau]]></dc:creator>
		<pubDate>Thu, 11 Jan 2018 02:29:05 +0000</pubDate>
		<guid isPermaLink="false">https://www.dragonflydigest.com/?p=20690#comment-487116</guid>

					<description><![CDATA[Anonymous, I think those sysctls work in the way you have described.]]></description>
			<content:encoded><![CDATA[<p>Anonymous, I think those sysctls work in the way you have described.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Anonymous		</title>
		<link>https://www.dragonflydigest.com/2018/01/08/more-meltdown-fixes/comment-page-1/#comment-487115</link>

		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Wed, 10 Jan 2018 20:22:23 +0000</pubDate>
		<guid isPermaLink="false">https://www.dragonflydigest.com/?p=20690#comment-487115</guid>

					<description><![CDATA[The sysctls are great.

Is it possible to turn isolated_user_pmap off, launch your trusted database and file server applications and then turn it back on?  Will the trusted applications continue to enjoy fast system calls in this scenario?

Since a newly purchased Xeon scale server is unlikely to be replaced soon, having a per process way of enabling or disabling the privacy mitigation for untrusted or trusted code could help tremendously with performance.]]></description>
			<content:encoded><![CDATA[<p>The sysctls are great.</p>
<p>Is it possible to turn isolated_user_pmap off, launch your trusted database and file server applications and then turn it back on?  Will the trusted applications continue to enjoy fast system calls in this scenario?</p>
<p>Since a newly purchased Xeon scale server is unlikely to be replaced soon, having a per process way of enabling or disabling the privacy mitigation for untrusted or trusted code could help tremendously with performance.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Justin Sherrill		</title>
		<link>https://www.dragonflydigest.com/2018/01/08/more-meltdown-fixes/comment-page-1/#comment-487112</link>

		<dc:creator><![CDATA[Justin Sherrill]]></dc:creator>
		<pubDate>Wed, 10 Jan 2018 15:28:33 +0000</pubDate>
		<guid isPermaLink="false">https://www.dragonflydigest.com/?p=20690#comment-487112</guid>

					<description><![CDATA[Anonymous: These mitigations are controlled by sysctls, so they can be disabled in any situation where you don&#039;t feel they are necessary.

Matthew Dillon posted another summary with specific sysctls mentioned; I&#039;ll post on it later today when I have time to write it up.]]></description>
			<content:encoded><![CDATA[<p>Anonymous: These mitigations are controlled by sysctls, so they can be disabled in any situation where you don&#8217;t feel they are necessary.</p>
<p>Matthew Dillon posted another summary with specific sysctls mentioned; I&#8217;ll post on it later today when I have time to write it up.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Anonymous		</title>
		<link>https://www.dragonflydigest.com/2018/01/08/more-meltdown-fixes/comment-page-1/#comment-487111</link>

		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Wed, 10 Jan 2018 03:01:37 +0000</pubDate>
		<guid isPermaLink="false">https://www.dragonflydigest.com/?p=20690#comment-487111</guid>

					<description><![CDATA[I understand the issues with JavaScript on the desktop, why would anyone be running rogue JavaScript or any other untrusted code on a server?

Even so, would it be possible to allow trusted user-space processes to enjoy fast system calls and only enable meltdown mitigation for processes running untrusted code?]]></description>
			<content:encoded><![CDATA[<p>I understand the issues with JavaScript on the desktop, why would anyone be running rogue JavaScript or any other untrusted code on a server?</p>
<p>Even so, would it be possible to allow trusted user-space processes to enjoy fast system calls and only enable meltdown mitigation for processes running untrusted code?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: max		</title>
		<link>https://www.dragonflydigest.com/2018/01/08/more-meltdown-fixes/comment-page-1/#comment-487108</link>

		<dc:creator><![CDATA[max]]></dc:creator>
		<pubDate>Tue, 09 Jan 2018 11:17:12 +0000</pubDate>
		<guid isPermaLink="false">https://www.dragonflydigest.com/?p=20690#comment-487108</guid>

					<description><![CDATA[Yes. Because all it takes is a bit of rogue javascript via a browser to be compromised]]></description>
			<content:encoded><![CDATA[<p>Yes. Because all it takes is a bit of rogue javascript via a browser to be compromised</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Anonymous		</title>
		<link>https://www.dragonflydigest.com/2018/01/08/more-meltdown-fixes/comment-page-1/#comment-487107</link>

		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Tue, 09 Jan 2018 04:25:01 +0000</pubDate>
		<guid isPermaLink="false">https://www.dragonflydigest.com/?p=20690#comment-487107</guid>

					<description><![CDATA[Honest question: unless youre hosting your server on a shared VM environment (eg AWS, Azure, etc) - should we even care about apply the spectre / meltdown patch?

If I either host all my server on my own hardware or I host on baremetal, seems like I should really worry about apply these patches]]></description>
			<content:encoded><![CDATA[<p>Honest question: unless youre hosting your server on a shared VM environment (eg AWS, Azure, etc) &#8211; should we even care about apply the spectre / meltdown patch?</p>
<p>If I either host all my server on my own hardware or I host on baremetal, seems like I should really worry about apply these patches</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
