In /etc/default/grub
, modify:
noibrs noibpb nopti nospectre_v2 nospectre_v1 l1tf=off nospec_store_bypass_disable no_stf_barrier mds=off tsx=on tsx_async_abort=off mitigations=off
Then sudo update-grub
from https:// make-linux-fast-again.com/ This domain does not seem to be maintained any longer.
noibrs noibpb nopti nospectre_v2 nospectre_v1 l1tf=off nospec_store_bypass_disable no_stf_barrier mds=off tsx=on tsx_async_abort=off mitigations=off
mitigations=off
is all you need. The setting turns off all mitigations that can be turned off. Repeating a long and, by the way, very obsolete list of individual vulnerability mitigation options is entirely unnecessary.The kernel parameters are documented in kernel sources
/Documentation/admin-guide/kernel-parameters.txt
, and also included as plain text in the kernel documentation page: https://www.kernel.org/doc/html/v6.2/admin-guide/kernel-parameters.html. Search formitigation=
, and read the list of mitigations that are turned off by this option. Replacev6.2
with your kernel version; https://www.kernel.org/doc/html/ lists all available versions. The part/admin-guide/kernel-parameters.html
never changes.