[$] The current state of kernel page-table isolation
At the end of October, the KAISER patch setwas unveiled; this work separates the page tables used by the kernel fromthose belonging to user space in an attempt to address x86 processor bugsthat can disclose the layout of the kernel to an attacker. Those patcheshave seen significant work in the weeks since their debut, but they appearto be approaching a final state. It seems like an appropriate time foranother look.