diff --git a/crypto/cryptlib.c b/crypto/cryptlib.c index d4b236284e1c3db49ac9e9ee285889a836b3d6ae..8a8fac3d13a3b6e910d4ef3ea0d9cd883a291183 100644 --- a/crypto/cryptlib.c +++ b/crypto/cryptlib.c @@ -144,12 +144,15 @@ void OPENSSL_cpuid_setup(void) if (trigger) return; trigger=1; - if ((env=getenv("OPENSSL_ia32cap"))) + if ((env=getenv("OPENSSL_ia32cap"))) { + int off = (env[0]=='~')?1:0; #if defined(_WIN32) - { if (!sscanf(env,"%I64i",&vec)) vec = strtoul(env,NULL,0); } + if (!sscanf(env+off,"%I64i",&vec)) vec = strtoul(env+off,NULL,0); #else - vec = strtoull(env,NULL,0); + vec = strtoull(env+off,NULL,0); #endif + if (off) vec = OPENSSL_ia32_cpuid()&~vec; + } else vec = OPENSSL_ia32_cpuid(); diff --git a/doc/crypto/OPENSSL_ia32cap.pod b/doc/crypto/OPENSSL_ia32cap.pod index 17189ed843aabb4ecdc34fb195ecfd7c916bf9c4..16f500fc76b6aff1aa6198d8bd17bafdfd69caca 100644 --- a/doc/crypto/OPENSSL_ia32cap.pod +++ b/doc/crypto/OPENSSL_ia32cap.pod @@ -61,10 +61,10 @@ capable CPU, but under control of OS that does not enable XMM registers. Even though you can manipulate the value programmatically, you most likely will find it more appropriate to set up an environment variable with the same name prior starting target application, e.g. on -Intel P4 processor 'env OPENSSL_ia32cap=0x16980010 apps/openssl', to -achieve same effect without modifying the application source code. -Alternatively you can reconfigure the toolkit with no-sse2 option and -recompile. +Intel P4 processor 'env OPENSSL_ia32cap=0x16980010 apps/openssl', or +better yet 'env OPENSSL_ia32cap=~0x1000000 apps/openssl' to achieve same +effect without modifying the application source code. Alternatively you +can reconfigure the toolkit with no-sse2 option and recompile. Less intuituve is clearing bit #28. The truth is that it's not copied from CPUID output verbatim, but is adjusted to reflect whether or not