Kernel needs to be built with retpolines
To mitigate the impact of SpectreV2 we need to build the operating system with retpolines and make sure that we properly change them and fallback when enhanced IBRS is present as well as properly enable the AMD variant.
Updated by John Levon 6 days ago
Work originally by Robert Mustacchi.
Note that as well as just enablign the compiler-generated retpoline thunks, we need to fix up all the assembly pieces we have to call the retpolines as needed.
We haven't done this for KMDB as it's hard to see an attack vector, and it's not really worth it.