You seem to be making the assumption that there is one L2. What if there are 100 L2s, and only one has write-access to IA32_SPEC_CTRL? Or what if there once was such an L2, but it's been gone for months? The current mechanism penalizes *all* L2s if any L2, ever, has write-access to IA32_SPEC_CTRL.