// // Kernel options // // XXX: Indirect branch restricted speculation (SPECTRE_IBRS) // is disabled by default as it can lead to significant // performance degradation. // option SPECTRE_IBRS no // Enable the IBRS CPU feature option SERIAL_DEBUG yes // Enable kmsg serial logging option USER_KMSG no // Show kmsg in user consoles option CPU_SMEP yes // Supervisor Memory Exec Protection option I8042_POLL yes // Use polling for the i8042