Date: Tue, 28 Feb 2023 20:24:12 +0100 From: Borislav Petkov <bp@xxxxxxxxx> > I'd prefer if VMMs did supply whatever they prefer to the guests > instead. None of those bits are used in the kernel for mitigations, as > you've realized. It is true that the kernel does not use those bits at all, but any codes could be run inside guests. One of examples is the following spectre/meltdown checker scipt used as de facto standard. https://github.com/speed47/spectre-meltdown-checker/blob/master/spectre-meltdown-checker.sh#L2768 Best regards, Takahiro Itazuri