Duprate wrote:add the microcode (it didn't work, maybe the kernel was not configured for that).
The running kernel is from the official Debian "linux-image-*" package, it should have the patches applied for Spectre and Meltdown, almost sure.
I could be that the microcode you added should be part of the initrd (to be loaded at boot), but just guessing, to be honest I know very little about Spectre and Meltdown, how to apply things, sorry.
EDIT: Don't know how you did add the microcode, but there's package "intel-microcode" in Sid repository, not sure if it helps, just saying.
The save file I converted to changes.squashfs.
I was wondering if that works OK also with deleted files (that are included in 01-filesystem.squashfs), did a quick test and it seems to work ok (masking the deleted files). Although it can be tested more. It worked well with aufs, but with overlay it may be different...
Fred