On Wed, Jan 31, 2018 at 1:59 PM, David Woodhouse <dwmw2@xxxxxxxxxxxxx> wrote: > I'm actually working on IBRS_ALL at the moment. > > I was tempted to *not* let the guests turn it off. Expose SPEC_CTRL but > just make it a no-op. Maybe we could convince Intel to add a LOCK bit to IA32_SPEC_CTRL like the one in IA32_FEATURE_CONTROL.