I also wanted to ask, are we going to enforce the same strategy on /dev/urandom ? If we don't because we fear application breakage or whatever, then there will always be some incentive against migrating to getrandom(). And if we do it, we know we have to take a reasonable approach making the change transparent enough for applications. That would too go in favor of a short timeout. Willy