-
The Security Tax in WSL3: Benchmarking Kernel Mitigations Against WSL 2.x
In our earlier look at The Security Tax in WSL 2, we showed how kernel-level mitigations for CPU speculative execution vulnerabilities (Spectre, Meltdown, Retbleed) imposed a steep penalty on developer tasks. On a real-world Go backend compilation workload, turning off mitigations slashed kernel system time by 45.7% and delivered a 31.7% drop in wall-clock compile time.
With the rollout of WSL v3.0.2 (running Linux kernel
6.18.40.1-microsoft-standard-WSL2), how does the security tax hold up today? Does modern hypervisor paravirtualization eliminate the overhead, or are developers still paying an invisible performance toll on syscall-heavy workloads?