Ubuntu will supply intel-compute-runtime without Spectre protection, reducing performance by 20%.

Ubuntu has decided to switch to supplying the intel-compute-runtime package by default, compiled with the NEO_DISABLE_MITIGATIONS flag that disables protection against Spectre class attacks. According to developers, this protection reduces the performance of the package by approximately 20%.

The intel-compute-runtime package includes components necessary for using OpenCL and OneAPI Level Zero on systems with Intel GPUs. When building the libraries included in the package, the presence of the NEO_DISABLE_MITIGATIONS flag disables the compiler options '-mretpoline -mindirect-branch=thunk -mfunction-return=thunk -mindirect-branch-register', which provide additional protection against Spectre. These options do not affect OpenCL performance and GPU-side operations but reduce the overhead when executing the code responsible for API operation.

Engineers responsible for security at Intel and Canonical concluded during discussions that the protection against Spectre implemented at the Compute Runtime level is no longer necessary, as the required protection is already present at the kernel level. The existing Spectre protection in Compute Runtime is mainly of interest to those using cores without adequate protection, and its benefits do not outweigh the observed performance drop. Furthermore, the Intel releases of Intel Graphics Compute Runtime are compiled with the NEO_DISABLE_MITIGATIONS flag set by default, disabling protection.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster