1
0
mirror of https://github.com/speed47/spectre-meltdown-checker synced 2024-12-31 16:45:45 +01:00

fix(spectre2): don't explain how to fix when NOT VULNERABLE

This commit is contained in:
Stéphane Lesimple 2018-04-15 20:55:55 +02:00
parent a3016134bd
commit c0108b9690

View File

@ -2366,7 +2366,7 @@ check_variant2_linux()
fi fi
# if we are in live mode, we can check for a lot more stuff and explain further # if we are in live mode, we can check for a lot more stuff and explain further
if [ "$opt_live" = 1 ]; then if [ "$opt_live" = 1 ] && [ "$vulnstatus" != "OK" ]; then
_explain_hypervisor="An updated CPU microcode will have IBRS/IBPB capabilities indicated in the Hardware Check section above. If you're running under an hypervisor (KVM, Xen, VirtualBox, VMware, ...), the hypervisor needs to be up to date to be able to export the new host CPU flags to the guest. You can run this script on the host to check if the host CPU is IBRS/IBPB. If it is, and it doesn't show up in the guest, upgrade the hypervisor." _explain_hypervisor="An updated CPU microcode will have IBRS/IBPB capabilities indicated in the Hardware Check section above. If you're running under an hypervisor (KVM, Xen, VirtualBox, VMware, ...), the hypervisor needs to be up to date to be able to export the new host CPU flags to the guest. You can run this script on the host to check if the host CPU is IBRS/IBPB. If it is, and it doesn't show up in the guest, upgrade the hypervisor."
# IBPB (amd & intel) # IBPB (amd & intel)
if [ "$ibpb_enabled" = 0 ] && ( is_intel || is_amd ); then if [ "$ibpb_enabled" = 0 ] && ( is_intel || is_amd ); then