mirror of
https://github.com/linuxkit/linuxkit.git
synced 2026-04-04 22:49:40 +00:00
This option is not enabled by default, but disables the BPF interpreter which can be used to inject speculative execution into the kernel. Enabled it as it seems like a good security measure. Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com>
See ../docs/kernels.md for more information on kernel builds.