Keeping your CPU safe from Spectre imposes serious performance penalty

Spectre and meldown
(Image credit: Graz University of Technology)

While conducting performance tests, a developer discovered that Spectre mitigations slowed his code by as much as 200%.

Spectre, along with Meltdown, are two extremely severe hardware vulnerabilities that affect Intel, IBM POWER, and some ARM-based processors. While Intel has since implemented hardware mitigations for the vulnerability in newer processors, older ones have to rely on software fixes that come with a performance penalty.

While testing his open source rr debugger, in his older Intel Skylake-equipped Linux laptop, Robert O'Callahan noticed that frequent system calls slowed down execution in user space, the memory that runs user processes and apps. 

“I assumed this was at least partly due to Spectre mitigations so I turned those off (with mitigations=off) and reran the test,” wrote O'Callahan, who immediately noticed a significant improvement in performance.

“So those Spectre mitigations make pre-optimization userspace run 2x slower (due to cache and TLB flushes I guess) and the whole workload overall 1.6x slower! Before Spectre mitigations, those system calls hardly slowed down userspace execution at all."

Performance penalty

It is well known that the software Spectre mitigations put a dent in processor performance, however their impact isn’t linear, as demonstrated by O'Callahan’s tests.

When quizzed by The Register, he reiterated that his tests demonstrate that system-call intensive workloads could experience significant performance hit on older CPUs like Skylake. 

"In my case I was able to rewrite the code to be much less system-call-intensive, but that won't always be possible," O'Callahan explained.

He was, however, quick to add that developers shouldn’t use the performance penalty as an excuse to disable the mitigations for Spectre and Meltdown.

"If you trust all the code running on the system you can turn these mitigations off safely. If you don't (e.g. because you use a web browser and you never know what ad scripts are doing), you should not turn off those mitigations IMHO," he noted, alluding perhaps to the proof-of-concept (PoC) code shared by Google in its bid to help web developers mitigate browser-based side-channel attacks.

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
The socket interface of the Intel Core Ultra processor
Got an Intel Core Ultra 200S CPU? These are the patches you need to help gaming performance – with one more update coming in January 2025
Windows fail
It looks like Microsoft might have broken Windows 11 24H2 again as performance plummets with Intel's latest CPUs
AMD logo
AMD patches high severity security flaw affecting Zen chips
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
Security
Intel slams Nvidia and AMD, claims chip giants have huge numbers of security flaws
Latest in Pro
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
AI writer
AI innovation in business: moving beyond scale to drive real results
Dark Web monitoring
A worrying critical security flaw in Apache Tomcat could let hackers take over servers with ease
Cyber-security
Dealing with the issue of CISO stress
Latest in News
A woman sitting in a chair looking at a Windows 11 laptop
Microsoft is supercharging Windows 11’s voice commands on Copilot+ PCs with Snapdragon CPUs, and fine-tuning a few Recall features
MacBook Air M4
Apple's rumored foldable iPad tipped to launch sooner than expected with an exciting software twist
A phone displaying the Google Messages logo
Google Messages could finally be getting this WhatsApp-style group chat feature
The Future Games Show Spring Showcase
The Future Games Show returns this week for its Spring Showcase, here's how to watch and what games to expect
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content