+ l += [OR(CmdlineCheck('self_protection', 'defconfig', 'l1tf', 'is not off'),
+ CmdlineCheck('self_protection', 'defconfig', 'l1tf', 'is not set'))]
+ l += [OR(CmdlineCheck('self_protection', 'defconfig', 'mds', 'is not off'),
+ CmdlineCheck('self_protection', 'defconfig', 'mds', 'is not set'))]
+ l += [OR(CmdlineCheck('self_protection', 'defconfig', 'tsx_async_abort', 'is not off'),
+ CmdlineCheck('self_protection', 'defconfig', 'tsx_async_abort', 'is not set'))]
+ l += [OR(CmdlineCheck('self_protection', 'defconfig', 'srbds', 'is not off'),
+ CmdlineCheck('self_protection', 'defconfig', 'srbds', 'is not set'))]
+ l += [OR(CmdlineCheck('self_protection', 'defconfig', 'mmio_stale_data', 'is not off'),
+ CmdlineCheck('self_protection', 'defconfig', 'mmio_stale_data', 'is not set'))]
+ l += [OR(CmdlineCheck('self_protection', 'defconfig', 'retbleed', 'is not off'),
+ CmdlineCheck('self_protection', 'defconfig', 'retbleed', 'is not set'))]
+ l += [OR(CmdlineCheck('self_protection', 'defconfig', 'kpti', 'is not off'),
+ CmdlineCheck('self_protection', 'defconfig', 'kpti', 'is not set'))]
+ l += [OR(CmdlineCheck('self_protection', 'defconfig', 'kvm.nx_huge_pages', 'is not off'),
+ CmdlineCheck('self_protection', 'defconfig', 'kvm.nx_huge_pages', 'is not set'))]