On Tue, Sep 24, 2019 at 7:16 AM Paolo Bonzini <pbonzini@xxxxxxxxxx> wrote: > Ugly stuff---Intel did the right thing in making the execution controls > "enable xxx" (xxx = RDRAND, RDSEED, etc.). I agree. RDPRU should have been disabled by default, or at least guarded by a new EFER bit, like MCOMMIT is.