Gentoo Archives: gentoo-hardened

From: Peter Hjalmarsson <xake@×××××××××.net>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Re: Re: Remove the pic use flag in the hardened amd64 profile.
Date: Wed, 02 Mar 2011 21:12:51
Message-Id: 1299100216.4696.1.camel@lillen
In Reply to: Re: [gentoo-hardened] Re: Remove the pic use flag in the hardened amd64 profile. by pageexec@freemail.hu
1 ons 2011-03-02 klockan 10:28 +0200 skrev
2 pageexec@××××××××.hu:
3 > On 1 Mar 2011 at 18:28, Anthony G. Basile wrote:
4 >
5 > > > in HVM mode
6 > > > i386 should be fine, amd64 should be dead slow.
7 > >
8 > > In my experience, both are fine. I run hardened x86, hardened amd64 and
9 > > hardened amd64 nomultilib as domU. The host is OpenSuse 11.3. I have
10 > > both KERNEXEC and UDEREF on, no noticeable problems.
11 >
12 > now that's interesting, does the host have/use EPT (or amd's equivalent)?
13 >
14 > > KVM is a different story, and I do see slowdown for amd64.
15 >
16 > this means that the slowdown is truly specific to some kvm/uderef interaction,
17 > not that i have an idea where to look still...
18 >
19 >
20 >
21
22 Are you missing anything you need to figure this out, like profiling
23 data?

Replies