https://www.intel.com/content/www/us/en/developer/articles/t...
Look at DOITM in that document — it is simply impossible for a userspace crypto library to set the required bit.
https://www.intel.com/content/www/us/en/developer/articles/t...
Look at DOITM in that document — it is simply impossible for a userspace crypto library to set the required bit.
User mode code can run in the correct mode. What it cannot do is toggle the mode on/off. Once toggled on, it works perfectly fine for userspace; this could become e.g. a per-process flag enabled by a prctl syscall, with the MSR adjusted during scheduler task switching.
I have absolutely nothing good to say about Intel’s design here.
CPUs have done just fine doing constant time math for decades. It’s at best a minor optimization to add data dependence, and Intel already knows (a) how to turn it off and (b) that it’s sometimes necessary to let it be turned off. Why can’t they add a reasonable mechanism to turn them off?
I agree it's not great.