The patch[*] is already in RHOS-13: $> git branch --contains 98eb85f rhos-13.0-patches [*] From RHOS-13 branch: $ git show 98eb85f commit 98eb85f29c5f0775de480d5ea2946dcbba85fe8a Author: Kashyap Chamarthy <kchamart> Date: Tue Jan 16 17:56:51 2018 +0100 libvirt: Allow to specify granular CPU feature flags The recent "Meltdown" CVE fixes have resulted in a critical performance penalty[*] that will impact every Nova guest with certain CPU models. I.e. assume you have applied all the "Meltdown" CVE fixes, and performed a cold reboot (explicit stop & start) of all Nova guests, for the updates to take effect. Now, if any guests that are booted with certain named virtual CPU models (e.g. "IvyBridge", "Westmere", etc), then those guests, will incur noticeable performance degradation[*], while being protected from the CVE itself. To alleviate this guest performance impact, it is now important to specify an obscure Intel CPU feature flag, 'PCID' (Process-Context ID) -- for the virtual CPU models that don't already include it (more on this below). To that end, this change will allow Nova to explicitly specify CPU feature flags via a new configuration attribute, `cpu_model_extra_flags`, e.g. in `nova.conf`: [...]
According to our records, this should be resolved by openstack-nova-17.0.3-0.20180420001141.el7ost. This build is available now.