-nosmep |cmdline| is not set |defconfig | self_protection | OK: not found
-nosmap |cmdline| is not set |defconfig | self_protection | OK: not found
-nokaslr |cmdline| is not set |defconfig | self_protection | OK: not found
-nopti |cmdline| is not set |defconfig | self_protection | OK: not found
-nospectre_v1 |cmdline| is not set |defconfig | self_protection | OK: not found
-nospectre_v2 |cmdline| is not set |defconfig | self_protection | OK: not found
-rodata |cmdline| 1 |defconfig | self_protection | OK: rodata not found
-init_on_alloc |cmdline| 1 | kspp | self_protection | FAIL: not found
-init_on_free |cmdline| 1 | kspp | self_protection | FAIL: not found
-slab_nomerge |cmdline| | kspp | self_protection | OK: CONFIG_SLAB_MERGE_DEFAULT "is not set"
-iommu.strict |cmdline| 1 | kspp | self_protection | FAIL: not found
-iommu.passthrough |cmdline| 0 | kspp | self_protection | OK: CONFIG_IOMMU_DEFAULT_PASSTHROUGH "is not set"
-hardened_usercopy |cmdline| 1 | kspp | self_protection | OK: CONFIG_HARDENED_USERCOPY "y"
-slab_common.usercopy_fallback |cmdline| 0 | kspp | self_protection | OK: CONFIG_HARDENED_USERCOPY_FALLBACK not found
-randomize_kstack_offset |cmdline| 1 | kspp | self_protection | OK: CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT "y"
-pti |cmdline| on | kspp | self_protection | FAIL: not found
-page_alloc.shuffle |cmdline| 1 | clipos | self_protection | FAIL: not found
-spectre_v2 |cmdline| on | clipos | self_protection | FAIL: not found
-vsyscall |cmdline| none | kspp |cut_attack_surface| FAIL: not found
-debugfs |cmdline| off | grsec |cut_attack_surface| FAIL: not found
-
-[+] Config check is finished: 'OK' - 97 / 'FAIL' - 101
+nosmep |cmdline| is not set |defconfig | self_protection | OK: is not found
+nosmap |cmdline| is not set |defconfig | self_protection | OK: is not found
+nokaslr |cmdline| is not set |defconfig | self_protection | OK: is not found
+nopti |cmdline| is not set |defconfig | self_protection | OK: is not found
+nospectre_v1 |cmdline| is not set |defconfig | self_protection | OK: is not found
+nospectre_v2 |cmdline| is not set |defconfig | self_protection | OK: is not found
+nospectre_bhb |cmdline| is not set |defconfig | self_protection | OK: is not found
+nospec_store_bypass_disable |cmdline| is not set |defconfig | self_protection | OK: is not found
+arm64.nobti |cmdline| is not set |defconfig | self_protection | OK: is not found
+arm64.nopauth |cmdline| is not set |defconfig | self_protection | OK: is not found
+arm64.nomte |cmdline| is not set |defconfig | self_protection | OK: is not found
+mitigations |cmdline| is not off |defconfig | self_protection | OK: mitigations is not found
+spectre_v2 |cmdline| is not off |defconfig | self_protection | OK: spectre_v2 is not found
+spectre_v2_user |cmdline| is not off |defconfig | self_protection | OK: spectre_v2_user is not found
+spec_store_bypass_disable |cmdline| is not off |defconfig | self_protection | OK: spec_store_bypass_disable is not found
+l1tf |cmdline| is not off |defconfig | self_protection | OK: l1tf is not found
+mds |cmdline| is not off |defconfig | self_protection | OK: mds is not found
+tsx_async_abort |cmdline| is not off |defconfig | self_protection | OK: tsx_async_abort is not found
+srbds |cmdline| is not off |defconfig | self_protection | OK: srbds is not found
+mmio_stale_data |cmdline| is not off |defconfig | self_protection | OK: mmio_stale_data is not found
+retbleed |cmdline| is not off |defconfig | self_protection | OK: retbleed is not found
+kpti |cmdline| is not off |defconfig | self_protection | OK: kpti is not found
+kvm.nx_huge_pages |cmdline| is not off |defconfig | self_protection | OK: kvm.nx_huge_pages is not found
+rodata |cmdline| 1 |defconfig | self_protection | OK: rodata is not found
+nosmt |cmdline| is present | kspp | self_protection | FAIL: is not present
+init_on_alloc |cmdline| 1 | kspp | self_protection | FAIL: is not found
+init_on_free |cmdline| 1 | kspp | self_protection | FAIL: is not found
+slab_nomerge |cmdline| is present | kspp | self_protection | OK: CONFIG_SLAB_MERGE_DEFAULT is "is not set"
+iommu.strict |cmdline| 1 | kspp | self_protection | FAIL: is not found
+iommu.passthrough |cmdline| 0 | kspp | self_protection | OK: CONFIG_IOMMU_DEFAULT_PASSTHROUGH is "is not set"
+hardened_usercopy |cmdline| 1 | kspp | self_protection | OK: CONFIG_HARDENED_USERCOPY is "y"
+slab_common.usercopy_fallback |cmdline| 0 | kspp | self_protection | OK: CONFIG_HARDENED_USERCOPY_FALLBACK is not found
+randomize_kstack_offset |cmdline| 1 | kspp | self_protection | OK: CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT is "y"
+pti |cmdline| on | kspp | self_protection | FAIL: is not found
+page_alloc.shuffle |cmdline| 1 | clipos | self_protection | FAIL: is not found
+iommu |cmdline| force | clipos | self_protection | FAIL: is not found
+tsx |cmdline| off |defconfig |cut_attack_surface| OK: CONFIG_X86_INTEL_TSX_MODE_OFF is "y"
+vsyscall |cmdline| none | kspp |cut_attack_surface| FAIL: is not found
+debugfs |cmdline| off | grsec |cut_attack_surface| FAIL: is not found
+sysrq_always_enabled |cmdline| is not set | my |cut_attack_surface| OK: is not found
+
+[+] Config check is finished: 'OK' - 122 / 'FAIL' - 101