random.c 52 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716
  1. // SPDX-License-Identifier: (GPL-2.0 OR BSD-3-Clause)
  2. /*
  3. * Copyright (C) 2017-2024 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
  4. * Copyright Matt Mackall <mpm@selenic.com>, 2003, 2004, 2005
  5. * Copyright Theodore Ts'o, 1994, 1995, 1996, 1997, 1998, 1999. All rights reserved.
  6. *
  7. * This driver produces cryptographically secure pseudorandom data. It is divided
  8. * into roughly six sections, each with a section header:
  9. *
  10. * - Initialization and readiness waiting.
  11. * - Fast key erasure RNG, the "crng".
  12. * - Entropy accumulation and extraction routines.
  13. * - Entropy collection routines.
  14. * - Userspace reader/writer interfaces.
  15. * - Sysctl interface.
  16. *
  17. * The high level overview is that there is one input pool, into which
  18. * various pieces of data are hashed. Prior to initialization, some of that
  19. * data is then "credited" as having a certain number of bits of entropy.
  20. * When enough bits of entropy are available, the hash is finalized and
  21. * handed as a key to a stream cipher that expands it indefinitely for
  22. * various consumers. This key is periodically refreshed as the various
  23. * entropy collectors, described below, add data to the input pool.
  24. */
  25. #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
  26. #include <linux/utsname.h>
  27. #include <linux/module.h>
  28. #include <linux/kernel.h>
  29. #include <linux/major.h>
  30. #include <linux/string.h>
  31. #include <linux/fcntl.h>
  32. #include <linux/slab.h>
  33. #include <linux/random.h>
  34. #include <linux/poll.h>
  35. #include <linux/init.h>
  36. #include <linux/fs.h>
  37. #include <linux/blkdev.h>
  38. #include <linux/interrupt.h>
  39. #include <linux/mm.h>
  40. #include <linux/nodemask.h>
  41. #include <linux/spinlock.h>
  42. #include <linux/kthread.h>
  43. #include <linux/percpu.h>
  44. #include <linux/ptrace.h>
  45. #include <linux/workqueue.h>
  46. #include <linux/irq.h>
  47. #include <linux/ratelimit.h>
  48. #include <linux/syscalls.h>
  49. #include <linux/completion.h>
  50. #include <linux/uuid.h>
  51. #include <linux/uaccess.h>
  52. #include <linux/suspend.h>
  53. #include <linux/siphash.h>
  54. #include <linux/sched/isolation.h>
  55. #include <crypto/chacha.h>
  56. #include <crypto/blake2s.h>
  57. #ifdef CONFIG_VDSO_GETRANDOM
  58. #include <vdso/getrandom.h>
  59. #include <vdso/datapage.h>
  60. #include <vdso/vsyscall.h>
  61. #endif
  62. #include <asm/archrandom.h>
  63. #include <asm/processor.h>
  64. #include <asm/irq.h>
  65. #include <asm/irq_regs.h>
  66. #include <asm/io.h>
  67. /*********************************************************************
  68. *
  69. * Initialization and readiness waiting.
  70. *
  71. * Much of the RNG infrastructure is devoted to various dependencies
  72. * being able to wait until the RNG has collected enough entropy and
  73. * is ready for safe consumption.
  74. *
  75. *********************************************************************/
  76. /*
  77. * crng_init is protected by base_crng->lock, and only increases
  78. * its value (from empty->early->ready).
  79. */
  80. static enum {
  81. CRNG_EMPTY = 0, /* Little to no entropy collected */
  82. CRNG_EARLY = 1, /* At least POOL_EARLY_BITS collected */
  83. CRNG_READY = 2 /* Fully initialized with POOL_READY_BITS collected */
  84. } crng_init __read_mostly = CRNG_EMPTY;
  85. static DEFINE_STATIC_KEY_FALSE(crng_is_ready);
  86. #define crng_ready() (static_branch_likely(&crng_is_ready) || crng_init >= CRNG_READY)
  87. /* Various types of waiters for crng_init->CRNG_READY transition. */
  88. static DECLARE_WAIT_QUEUE_HEAD(crng_init_wait);
  89. static struct fasync_struct *fasync;
  90. static ATOMIC_NOTIFIER_HEAD(random_ready_notifier);
  91. /* Control how we warn userspace. */
  92. static struct ratelimit_state urandom_warning =
  93. RATELIMIT_STATE_INIT_FLAGS("urandom_warning", HZ, 3, RATELIMIT_MSG_ON_RELEASE);
  94. static int ratelimit_disable __read_mostly = 0;
  95. module_param_named(ratelimit_disable, ratelimit_disable, int, 0644);
  96. MODULE_PARM_DESC(ratelimit_disable, "Disable random ratelimit suppression");
  97. /*
  98. * Returns whether or not the input pool has been seeded and thus guaranteed
  99. * to supply cryptographically secure random numbers. This applies to: the
  100. * /dev/urandom device, the get_random_bytes function, and the get_random_{u8,
  101. * u16,u32,u64,long} family of functions.
  102. *
  103. * Returns: true if the input pool has been seeded.
  104. * false if the input pool has not been seeded.
  105. */
  106. bool rng_is_initialized(void)
  107. {
  108. return crng_ready();
  109. }
  110. EXPORT_SYMBOL(rng_is_initialized);
  111. static void __cold crng_set_ready(struct work_struct *work)
  112. {
  113. static_branch_enable(&crng_is_ready);
  114. }
  115. /* Used by wait_for_random_bytes(), and considered an entropy collector, below. */
  116. static void try_to_generate_entropy(void);
  117. /*
  118. * Wait for the input pool to be seeded and thus guaranteed to supply
  119. * cryptographically secure random numbers. This applies to: the /dev/urandom
  120. * device, the get_random_bytes function, and the get_random_{u8,u16,u32,u64,
  121. * long} family of functions. Using any of these functions without first
  122. * calling this function forfeits the guarantee of security.
  123. *
  124. * Returns: 0 if the input pool has been seeded.
  125. * -ERESTARTSYS if the function was interrupted by a signal.
  126. */
  127. int wait_for_random_bytes(void)
  128. {
  129. while (!crng_ready()) {
  130. int ret;
  131. try_to_generate_entropy();
  132. ret = wait_event_interruptible_timeout(crng_init_wait, crng_ready(), HZ);
  133. if (ret)
  134. return ret > 0 ? 0 : ret;
  135. }
  136. return 0;
  137. }
  138. EXPORT_SYMBOL(wait_for_random_bytes);
  139. /*
  140. * Add a callback function that will be invoked when the crng is initialised,
  141. * or immediately if it already has been. Only use this is you are absolutely
  142. * sure it is required. Most users should instead be able to test
  143. * `rng_is_initialized()` on demand, or make use of `get_random_bytes_wait()`.
  144. */
  145. int __cold execute_with_initialized_rng(struct notifier_block *nb)
  146. {
  147. unsigned long flags;
  148. int ret = 0;
  149. spin_lock_irqsave(&random_ready_notifier.lock, flags);
  150. if (crng_ready())
  151. nb->notifier_call(nb, 0, NULL);
  152. else
  153. ret = raw_notifier_chain_register((struct raw_notifier_head *)&random_ready_notifier.head, nb);
  154. spin_unlock_irqrestore(&random_ready_notifier.lock, flags);
  155. return ret;
  156. }
  157. /*********************************************************************
  158. *
  159. * Fast key erasure RNG, the "crng".
  160. *
  161. * These functions expand entropy from the entropy extractor into
  162. * long streams for external consumption using the "fast key erasure"
  163. * RNG described at <https://blog.cr.yp.to/20170723-random.html>.
  164. *
  165. * There are a few exported interfaces for use by other drivers:
  166. *
  167. * void get_random_bytes(void *buf, size_t len)
  168. * u8 get_random_u8()
  169. * u16 get_random_u16()
  170. * u32 get_random_u32()
  171. * u32 get_random_u32_below(u32 ceil)
  172. * u32 get_random_u32_above(u32 floor)
  173. * u32 get_random_u32_inclusive(u32 floor, u32 ceil)
  174. * u64 get_random_u64()
  175. * unsigned long get_random_long()
  176. *
  177. * These interfaces will return the requested number of random bytes
  178. * into the given buffer or as a return value. This is equivalent to
  179. * a read from /dev/urandom. The u8, u16, u32, u64, long family of
  180. * functions may be higher performance for one-off random integers,
  181. * because they do a bit of buffering and do not invoke reseeding
  182. * until the buffer is emptied.
  183. *
  184. *********************************************************************/
  185. enum {
  186. CRNG_RESEED_START_INTERVAL = HZ,
  187. CRNG_RESEED_INTERVAL = 60 * HZ
  188. };
  189. static struct {
  190. u8 key[CHACHA_KEY_SIZE] __aligned(__alignof__(long));
  191. unsigned long generation;
  192. spinlock_t lock;
  193. } base_crng = {
  194. .lock = __SPIN_LOCK_UNLOCKED(base_crng.lock)
  195. };
  196. struct crng {
  197. u8 key[CHACHA_KEY_SIZE];
  198. unsigned long generation;
  199. local_lock_t lock;
  200. };
  201. static DEFINE_PER_CPU(struct crng, crngs) = {
  202. .generation = ULONG_MAX,
  203. .lock = INIT_LOCAL_LOCK(crngs.lock),
  204. };
  205. /*
  206. * Return the interval until the next reseeding, which is normally
  207. * CRNG_RESEED_INTERVAL, but during early boot, it is at an interval
  208. * proportional to the uptime.
  209. */
  210. static unsigned int crng_reseed_interval(void)
  211. {
  212. static bool early_boot = true;
  213. if (unlikely(READ_ONCE(early_boot))) {
  214. time64_t uptime = ktime_get_seconds();
  215. if (uptime >= CRNG_RESEED_INTERVAL / HZ * 2)
  216. WRITE_ONCE(early_boot, false);
  217. else
  218. return max_t(unsigned int, CRNG_RESEED_START_INTERVAL,
  219. (unsigned int)uptime / 2 * HZ);
  220. }
  221. return CRNG_RESEED_INTERVAL;
  222. }
  223. /* Used by crng_reseed() and crng_make_state() to extract a new seed from the input pool. */
  224. static void extract_entropy(void *buf, size_t len);
  225. /* This extracts a new crng key from the input pool. */
  226. static void crng_reseed(struct work_struct *work)
  227. {
  228. static DECLARE_DELAYED_WORK(next_reseed, crng_reseed);
  229. unsigned long flags;
  230. unsigned long next_gen;
  231. u8 key[CHACHA_KEY_SIZE];
  232. /* Immediately schedule the next reseeding, so that it fires sooner rather than later. */
  233. if (likely(system_dfl_wq))
  234. queue_delayed_work(system_dfl_wq, &next_reseed, crng_reseed_interval());
  235. extract_entropy(key, sizeof(key));
  236. /*
  237. * We copy the new key into the base_crng, overwriting the old one,
  238. * and update the generation counter. We avoid hitting ULONG_MAX,
  239. * because the per-cpu crngs are initialized to ULONG_MAX, so this
  240. * forces new CPUs that come online to always initialize.
  241. */
  242. spin_lock_irqsave(&base_crng.lock, flags);
  243. memcpy(base_crng.key, key, sizeof(base_crng.key));
  244. next_gen = base_crng.generation + 1;
  245. if (next_gen == ULONG_MAX)
  246. ++next_gen;
  247. WRITE_ONCE(base_crng.generation, next_gen);
  248. #ifdef CONFIG_VDSO_GETRANDOM
  249. /* base_crng.generation's invalid value is ULONG_MAX, while
  250. * vdso_k_rng_data->generation's invalid value is 0, so add one to the
  251. * former to arrive at the latter. Use smp_store_release so that this
  252. * is ordered with the write above to base_crng.generation. Pairs with
  253. * the smp_rmb() before the syscall in the vDSO code.
  254. *
  255. * Cast to unsigned long for 32-bit architectures, since atomic 64-bit
  256. * operations are not supported on those architectures. This is safe
  257. * because base_crng.generation is a 32-bit value. On big-endian
  258. * architectures it will be stored in the upper 32 bits, but that's okay
  259. * because the vDSO side only checks whether the value changed, without
  260. * actually using or interpreting the value.
  261. */
  262. smp_store_release((unsigned long *)&vdso_k_rng_data->generation, next_gen + 1);
  263. #endif
  264. if (!static_branch_likely(&crng_is_ready))
  265. crng_init = CRNG_READY;
  266. spin_unlock_irqrestore(&base_crng.lock, flags);
  267. memzero_explicit(key, sizeof(key));
  268. }
  269. /*
  270. * This generates a ChaCha block using the provided key, and then
  271. * immediately overwrites that key with half the block. It returns
  272. * the resultant ChaCha state to the user, along with the second
  273. * half of the block containing 32 bytes of random data that may
  274. * be used; random_data_len may not be greater than 32.
  275. *
  276. * The returned ChaCha state contains within it a copy of the old
  277. * key value, at index 4, so the state should always be zeroed out
  278. * immediately after using in order to maintain forward secrecy.
  279. * If the state cannot be erased in a timely manner, then it is
  280. * safer to set the random_data parameter to &chacha_state->x[4]
  281. * so that this function overwrites it before returning.
  282. */
  283. static void crng_fast_key_erasure(u8 key[CHACHA_KEY_SIZE],
  284. struct chacha_state *chacha_state,
  285. u8 *random_data, size_t random_data_len)
  286. {
  287. u8 first_block[CHACHA_BLOCK_SIZE];
  288. BUG_ON(random_data_len > 32);
  289. chacha_init_consts(chacha_state);
  290. memcpy(&chacha_state->x[4], key, CHACHA_KEY_SIZE);
  291. memset(&chacha_state->x[12], 0, sizeof(u32) * 4);
  292. chacha20_block(chacha_state, first_block);
  293. memcpy(key, first_block, CHACHA_KEY_SIZE);
  294. memcpy(random_data, first_block + CHACHA_KEY_SIZE, random_data_len);
  295. memzero_explicit(first_block, sizeof(first_block));
  296. }
  297. /*
  298. * This function returns a ChaCha state that you may use for generating
  299. * random data. It also returns up to 32 bytes on its own of random data
  300. * that may be used; random_data_len may not be greater than 32.
  301. */
  302. static void crng_make_state(struct chacha_state *chacha_state,
  303. u8 *random_data, size_t random_data_len)
  304. {
  305. unsigned long flags;
  306. struct crng *crng;
  307. BUG_ON(random_data_len > 32);
  308. /*
  309. * For the fast path, we check whether we're ready, unlocked first, and
  310. * then re-check once locked later. In the case where we're really not
  311. * ready, we do fast key erasure with the base_crng directly, extracting
  312. * when crng_init is CRNG_EMPTY.
  313. */
  314. if (!crng_ready()) {
  315. bool ready;
  316. spin_lock_irqsave(&base_crng.lock, flags);
  317. ready = crng_ready();
  318. if (!ready) {
  319. if (crng_init == CRNG_EMPTY)
  320. extract_entropy(base_crng.key, sizeof(base_crng.key));
  321. crng_fast_key_erasure(base_crng.key, chacha_state,
  322. random_data, random_data_len);
  323. }
  324. spin_unlock_irqrestore(&base_crng.lock, flags);
  325. if (!ready)
  326. return;
  327. }
  328. local_lock_irqsave(&crngs.lock, flags);
  329. crng = raw_cpu_ptr(&crngs);
  330. /*
  331. * If our per-cpu crng is older than the base_crng, then it means
  332. * somebody reseeded the base_crng. In that case, we do fast key
  333. * erasure on the base_crng, and use its output as the new key
  334. * for our per-cpu crng. This brings us up to date with base_crng.
  335. */
  336. if (unlikely(crng->generation != READ_ONCE(base_crng.generation))) {
  337. spin_lock(&base_crng.lock);
  338. crng_fast_key_erasure(base_crng.key, chacha_state,
  339. crng->key, sizeof(crng->key));
  340. crng->generation = base_crng.generation;
  341. spin_unlock(&base_crng.lock);
  342. }
  343. /*
  344. * Finally, when we've made it this far, our per-cpu crng has an up
  345. * to date key, and we can do fast key erasure with it to produce
  346. * some random data and a ChaCha state for the caller. All other
  347. * branches of this function are "unlikely", so most of the time we
  348. * should wind up here immediately.
  349. */
  350. crng_fast_key_erasure(crng->key, chacha_state, random_data, random_data_len);
  351. local_unlock_irqrestore(&crngs.lock, flags);
  352. }
  353. static void _get_random_bytes(void *buf, size_t len)
  354. {
  355. struct chacha_state chacha_state;
  356. u8 tmp[CHACHA_BLOCK_SIZE];
  357. size_t first_block_len;
  358. if (!len)
  359. return;
  360. first_block_len = min_t(size_t, 32, len);
  361. crng_make_state(&chacha_state, buf, first_block_len);
  362. len -= first_block_len;
  363. buf += first_block_len;
  364. while (len) {
  365. if (len < CHACHA_BLOCK_SIZE) {
  366. chacha20_block(&chacha_state, tmp);
  367. memcpy(buf, tmp, len);
  368. memzero_explicit(tmp, sizeof(tmp));
  369. break;
  370. }
  371. chacha20_block(&chacha_state, buf);
  372. if (unlikely(chacha_state.x[12] == 0))
  373. ++chacha_state.x[13];
  374. len -= CHACHA_BLOCK_SIZE;
  375. buf += CHACHA_BLOCK_SIZE;
  376. }
  377. chacha_zeroize_state(&chacha_state);
  378. }
  379. /*
  380. * This returns random bytes in arbitrary quantities. The quality of the
  381. * random bytes is as good as /dev/urandom. In order to ensure that the
  382. * randomness provided by this function is okay, the function
  383. * wait_for_random_bytes() should be called and return 0 at least once
  384. * at any point prior.
  385. */
  386. void get_random_bytes(void *buf, size_t len)
  387. {
  388. _get_random_bytes(buf, len);
  389. }
  390. EXPORT_SYMBOL(get_random_bytes);
  391. static ssize_t get_random_bytes_user(struct iov_iter *iter)
  392. {
  393. struct chacha_state chacha_state;
  394. u8 block[CHACHA_BLOCK_SIZE];
  395. size_t ret = 0, copied;
  396. if (unlikely(!iov_iter_count(iter)))
  397. return 0;
  398. /*
  399. * Immediately overwrite the ChaCha key at index 4 with random
  400. * bytes, in case userspace causes copy_to_iter() below to sleep
  401. * forever, so that we still retain forward secrecy in that case.
  402. */
  403. crng_make_state(&chacha_state, (u8 *)&chacha_state.x[4],
  404. CHACHA_KEY_SIZE);
  405. /*
  406. * However, if we're doing a read of len <= 32, we don't need to
  407. * use chacha_state after, so we can simply return those bytes to
  408. * the user directly.
  409. */
  410. if (iov_iter_count(iter) <= CHACHA_KEY_SIZE) {
  411. ret = copy_to_iter(&chacha_state.x[4], CHACHA_KEY_SIZE, iter);
  412. goto out_zero_chacha;
  413. }
  414. for (;;) {
  415. chacha20_block(&chacha_state, block);
  416. if (unlikely(chacha_state.x[12] == 0))
  417. ++chacha_state.x[13];
  418. copied = copy_to_iter(block, sizeof(block), iter);
  419. ret += copied;
  420. if (!iov_iter_count(iter) || copied != sizeof(block))
  421. break;
  422. BUILD_BUG_ON(PAGE_SIZE % sizeof(block) != 0);
  423. if (ret % PAGE_SIZE == 0) {
  424. if (signal_pending(current))
  425. break;
  426. cond_resched();
  427. }
  428. }
  429. memzero_explicit(block, sizeof(block));
  430. out_zero_chacha:
  431. chacha_zeroize_state(&chacha_state);
  432. return ret ? ret : -EFAULT;
  433. }
  434. /*
  435. * Batched entropy returns random integers. The quality of the random
  436. * number is as good as /dev/urandom. In order to ensure that the randomness
  437. * provided by this function is okay, the function wait_for_random_bytes()
  438. * should be called and return 0 at least once at any point prior.
  439. */
  440. #define DEFINE_BATCHED_ENTROPY(type) \
  441. struct batch_ ##type { \
  442. /* \
  443. * We make this 1.5x a ChaCha block, so that we get the \
  444. * remaining 32 bytes from fast key erasure, plus one full \
  445. * block from the detached ChaCha state. We can increase \
  446. * the size of this later if needed so long as we keep the \
  447. * formula of (integer_blocks + 0.5) * CHACHA_BLOCK_SIZE. \
  448. */ \
  449. type entropy[CHACHA_BLOCK_SIZE * 3 / (2 * sizeof(type))]; \
  450. local_lock_t lock; \
  451. unsigned long generation; \
  452. unsigned int position; \
  453. }; \
  454. \
  455. static DEFINE_PER_CPU(struct batch_ ##type, batched_entropy_ ##type) = { \
  456. .lock = INIT_LOCAL_LOCK(batched_entropy_ ##type.lock), \
  457. .position = UINT_MAX \
  458. }; \
  459. \
  460. type get_random_ ##type(void) \
  461. { \
  462. type ret; \
  463. unsigned long flags; \
  464. struct batch_ ##type *batch; \
  465. unsigned long next_gen; \
  466. \
  467. if (!crng_ready()) { \
  468. _get_random_bytes(&ret, sizeof(ret)); \
  469. return ret; \
  470. } \
  471. \
  472. local_lock_irqsave(&batched_entropy_ ##type.lock, flags); \
  473. batch = raw_cpu_ptr(&batched_entropy_##type); \
  474. \
  475. next_gen = READ_ONCE(base_crng.generation); \
  476. if (batch->position >= ARRAY_SIZE(batch->entropy) || \
  477. next_gen != batch->generation) { \
  478. _get_random_bytes(batch->entropy, sizeof(batch->entropy)); \
  479. batch->position = 0; \
  480. batch->generation = next_gen; \
  481. } \
  482. \
  483. ret = batch->entropy[batch->position]; \
  484. batch->entropy[batch->position] = 0; \
  485. ++batch->position; \
  486. local_unlock_irqrestore(&batched_entropy_ ##type.lock, flags); \
  487. return ret; \
  488. } \
  489. EXPORT_SYMBOL(get_random_ ##type);
  490. DEFINE_BATCHED_ENTROPY(u8)
  491. DEFINE_BATCHED_ENTROPY(u16)
  492. DEFINE_BATCHED_ENTROPY(u32)
  493. DEFINE_BATCHED_ENTROPY(u64)
  494. u32 __get_random_u32_below(u32 ceil)
  495. {
  496. /*
  497. * This is the slow path for variable ceil. It is still fast, most of
  498. * the time, by doing traditional reciprocal multiplication and
  499. * opportunistically comparing the lower half to ceil itself, before
  500. * falling back to computing a larger bound, and then rejecting samples
  501. * whose lower half would indicate a range indivisible by ceil. The use
  502. * of `-ceil % ceil` is analogous to `2^32 % ceil`, but is computable
  503. * in 32-bits.
  504. */
  505. u32 rand = get_random_u32();
  506. u64 mult;
  507. /*
  508. * This function is technically undefined for ceil == 0, and in fact
  509. * for the non-underscored constant version in the header, we build bug
  510. * on that. But for the non-constant case, it's convenient to have that
  511. * evaluate to being a straight call to get_random_u32(), so that
  512. * get_random_u32_inclusive() can work over its whole range without
  513. * undefined behavior.
  514. */
  515. if (unlikely(!ceil))
  516. return rand;
  517. mult = (u64)ceil * rand;
  518. if (unlikely((u32)mult < ceil)) {
  519. u32 bound = -ceil % ceil;
  520. while (unlikely((u32)mult < bound))
  521. mult = (u64)ceil * get_random_u32();
  522. }
  523. return mult >> 32;
  524. }
  525. EXPORT_SYMBOL(__get_random_u32_below);
  526. #ifdef CONFIG_SMP
  527. /*
  528. * This function is called when the CPU is coming up, with entry
  529. * CPUHP_RANDOM_PREPARE, which comes before CPUHP_WORKQUEUE_PREP.
  530. */
  531. int __cold random_prepare_cpu(unsigned int cpu)
  532. {
  533. /*
  534. * When the cpu comes back online, immediately invalidate both
  535. * the per-cpu crng and all batches, so that we serve fresh
  536. * randomness.
  537. */
  538. per_cpu_ptr(&crngs, cpu)->generation = ULONG_MAX;
  539. per_cpu_ptr(&batched_entropy_u8, cpu)->position = UINT_MAX;
  540. per_cpu_ptr(&batched_entropy_u16, cpu)->position = UINT_MAX;
  541. per_cpu_ptr(&batched_entropy_u32, cpu)->position = UINT_MAX;
  542. per_cpu_ptr(&batched_entropy_u64, cpu)->position = UINT_MAX;
  543. return 0;
  544. }
  545. #endif
  546. /**********************************************************************
  547. *
  548. * Entropy accumulation and extraction routines.
  549. *
  550. * Callers may add entropy via:
  551. *
  552. * static void mix_pool_bytes(const void *buf, size_t len)
  553. *
  554. * After which, if added entropy should be credited:
  555. *
  556. * static void credit_init_bits(size_t bits)
  557. *
  558. * Finally, extract entropy via:
  559. *
  560. * static void extract_entropy(void *buf, size_t len)
  561. *
  562. **********************************************************************/
  563. enum {
  564. POOL_BITS = BLAKE2S_HASH_SIZE * 8,
  565. POOL_READY_BITS = POOL_BITS, /* When crng_init->CRNG_READY */
  566. POOL_EARLY_BITS = POOL_READY_BITS / 2 /* When crng_init->CRNG_EARLY */
  567. };
  568. static struct {
  569. struct blake2s_ctx hash;
  570. spinlock_t lock;
  571. unsigned int init_bits;
  572. } input_pool = {
  573. .hash.h = { BLAKE2S_IV0 ^ (0x01010000 | BLAKE2S_HASH_SIZE),
  574. BLAKE2S_IV1, BLAKE2S_IV2, BLAKE2S_IV3, BLAKE2S_IV4,
  575. BLAKE2S_IV5, BLAKE2S_IV6, BLAKE2S_IV7 },
  576. .hash.outlen = BLAKE2S_HASH_SIZE,
  577. .lock = __SPIN_LOCK_UNLOCKED(input_pool.lock),
  578. };
  579. static void _mix_pool_bytes(const void *buf, size_t len)
  580. {
  581. blake2s_update(&input_pool.hash, buf, len);
  582. }
  583. /*
  584. * This function adds bytes into the input pool. It does not
  585. * update the initialization bit counter; the caller should call
  586. * credit_init_bits if this is appropriate.
  587. */
  588. static void mix_pool_bytes(const void *buf, size_t len)
  589. {
  590. unsigned long flags;
  591. spin_lock_irqsave(&input_pool.lock, flags);
  592. _mix_pool_bytes(buf, len);
  593. spin_unlock_irqrestore(&input_pool.lock, flags);
  594. }
  595. /*
  596. * This is an HKDF-like construction for using the hashed collected entropy
  597. * as a PRF key, that's then expanded block-by-block.
  598. */
  599. static void extract_entropy(void *buf, size_t len)
  600. {
  601. unsigned long flags;
  602. u8 seed[BLAKE2S_HASH_SIZE], next_key[BLAKE2S_HASH_SIZE];
  603. struct {
  604. unsigned long rdseed[32 / sizeof(long)];
  605. size_t counter;
  606. } block;
  607. size_t i, longs;
  608. for (i = 0; i < ARRAY_SIZE(block.rdseed);) {
  609. longs = arch_get_random_seed_longs(&block.rdseed[i], ARRAY_SIZE(block.rdseed) - i);
  610. if (longs) {
  611. i += longs;
  612. continue;
  613. }
  614. longs = arch_get_random_longs(&block.rdseed[i], ARRAY_SIZE(block.rdseed) - i);
  615. if (longs) {
  616. i += longs;
  617. continue;
  618. }
  619. block.rdseed[i++] = random_get_entropy();
  620. }
  621. spin_lock_irqsave(&input_pool.lock, flags);
  622. /* seed = HASHPRF(last_key, entropy_input) */
  623. blake2s_final(&input_pool.hash, seed);
  624. /* next_key = HASHPRF(seed, RDSEED || 0) */
  625. block.counter = 0;
  626. blake2s(seed, sizeof(seed), (const u8 *)&block, sizeof(block), next_key, sizeof(next_key));
  627. blake2s_init_key(&input_pool.hash, BLAKE2S_HASH_SIZE, next_key, sizeof(next_key));
  628. spin_unlock_irqrestore(&input_pool.lock, flags);
  629. memzero_explicit(next_key, sizeof(next_key));
  630. while (len) {
  631. i = min_t(size_t, len, BLAKE2S_HASH_SIZE);
  632. /* output = HASHPRF(seed, RDSEED || ++counter) */
  633. ++block.counter;
  634. blake2s(seed, sizeof(seed), (const u8 *)&block, sizeof(block), buf, i);
  635. len -= i;
  636. buf += i;
  637. }
  638. memzero_explicit(seed, sizeof(seed));
  639. memzero_explicit(&block, sizeof(block));
  640. }
  641. #define credit_init_bits(bits) if (!crng_ready()) _credit_init_bits(bits)
  642. static void __cold _credit_init_bits(size_t bits)
  643. {
  644. static DECLARE_WORK(set_ready, crng_set_ready);
  645. unsigned int new, orig, add;
  646. unsigned long flags;
  647. int m;
  648. if (!bits)
  649. return;
  650. add = min_t(size_t, bits, POOL_BITS);
  651. orig = READ_ONCE(input_pool.init_bits);
  652. do {
  653. new = min_t(unsigned int, POOL_BITS, orig + add);
  654. } while (!try_cmpxchg(&input_pool.init_bits, &orig, new));
  655. if (orig < POOL_READY_BITS && new >= POOL_READY_BITS) {
  656. crng_reseed(NULL); /* Sets crng_init to CRNG_READY under base_crng.lock. */
  657. if (system_dfl_wq)
  658. queue_work(system_dfl_wq, &set_ready);
  659. atomic_notifier_call_chain(&random_ready_notifier, 0, NULL);
  660. #ifdef CONFIG_VDSO_GETRANDOM
  661. WRITE_ONCE(vdso_k_rng_data->is_ready, true);
  662. #endif
  663. wake_up_interruptible(&crng_init_wait);
  664. kill_fasync(&fasync, SIGIO, POLL_IN);
  665. pr_notice("crng init done\n");
  666. m = ratelimit_state_get_miss(&urandom_warning);
  667. if (m)
  668. pr_notice("%d urandom warning(s) missed due to ratelimiting\n", m);
  669. } else if (orig < POOL_EARLY_BITS && new >= POOL_EARLY_BITS) {
  670. spin_lock_irqsave(&base_crng.lock, flags);
  671. /* Check if crng_init is CRNG_EMPTY, to avoid race with crng_reseed(). */
  672. if (crng_init == CRNG_EMPTY) {
  673. extract_entropy(base_crng.key, sizeof(base_crng.key));
  674. crng_init = CRNG_EARLY;
  675. }
  676. spin_unlock_irqrestore(&base_crng.lock, flags);
  677. }
  678. }
  679. /**********************************************************************
  680. *
  681. * Entropy collection routines.
  682. *
  683. * The following exported functions are used for pushing entropy into
  684. * the above entropy accumulation routines:
  685. *
  686. * void add_device_randomness(const void *buf, size_t len);
  687. * void add_hwgenerator_randomness(const void *buf, size_t len, size_t entropy, bool sleep_after);
  688. * void add_bootloader_randomness(const void *buf, size_t len);
  689. * void add_vmfork_randomness(const void *unique_vm_id, size_t len);
  690. * void add_interrupt_randomness(int irq);
  691. * void add_input_randomness(unsigned int type, unsigned int code, unsigned int value);
  692. * void add_disk_randomness(struct gendisk *disk);
  693. *
  694. * add_device_randomness() adds data to the input pool that
  695. * is likely to differ between two devices (or possibly even per boot).
  696. * This would be things like MAC addresses or serial numbers, or the
  697. * read-out of the RTC. This does *not* credit any actual entropy to
  698. * the pool, but it initializes the pool to different values for devices
  699. * that might otherwise be identical and have very little entropy
  700. * available to them (particularly common in the embedded world).
  701. *
  702. * add_hwgenerator_randomness() is for true hardware RNGs, and will credit
  703. * entropy as specified by the caller. If the entropy pool is full it will
  704. * block until more entropy is needed.
  705. *
  706. * add_bootloader_randomness() is called by bootloader drivers, such as EFI
  707. * and device tree, and credits its input depending on whether or not the
  708. * command line option 'random.trust_bootloader' is set.
  709. *
  710. * add_vmfork_randomness() adds a unique (but not necessarily secret) ID
  711. * representing the current instance of a VM to the pool, without crediting,
  712. * and then force-reseeds the crng so that it takes effect immediately.
  713. *
  714. * add_interrupt_randomness() uses the interrupt timing as random
  715. * inputs to the entropy pool. Using the cycle counters and the irq source
  716. * as inputs, it feeds the input pool roughly once a second or after 64
  717. * interrupts, crediting 1 bit of entropy for whichever comes first.
  718. *
  719. * add_input_randomness() uses the input layer interrupt timing, as well
  720. * as the event type information from the hardware.
  721. *
  722. * add_disk_randomness() uses what amounts to the seek time of block
  723. * layer request events, on a per-disk_devt basis, as input to the
  724. * entropy pool. Note that high-speed solid state drives with very low
  725. * seek times do not make for good sources of entropy, as their seek
  726. * times are usually fairly consistent.
  727. *
  728. * The last two routines try to estimate how many bits of entropy
  729. * to credit. They do this by keeping track of the first and second
  730. * order deltas of the event timings.
  731. *
  732. **********************************************************************/
  733. static bool trust_cpu __initdata = true;
  734. static bool trust_bootloader __initdata = true;
  735. static int __init parse_trust_cpu(char *arg)
  736. {
  737. return kstrtobool(arg, &trust_cpu);
  738. }
  739. static int __init parse_trust_bootloader(char *arg)
  740. {
  741. return kstrtobool(arg, &trust_bootloader);
  742. }
  743. early_param("random.trust_cpu", parse_trust_cpu);
  744. early_param("random.trust_bootloader", parse_trust_bootloader);
  745. static int random_pm_notification(struct notifier_block *nb, unsigned long action, void *data)
  746. {
  747. unsigned long flags, entropy = random_get_entropy();
  748. /*
  749. * Encode a representation of how long the system has been suspended,
  750. * in a way that is distinct from prior system suspends.
  751. */
  752. ktime_t stamps[] = { ktime_get(), ktime_get_boottime(), ktime_get_real() };
  753. spin_lock_irqsave(&input_pool.lock, flags);
  754. _mix_pool_bytes(&action, sizeof(action));
  755. _mix_pool_bytes(stamps, sizeof(stamps));
  756. _mix_pool_bytes(&entropy, sizeof(entropy));
  757. spin_unlock_irqrestore(&input_pool.lock, flags);
  758. if (crng_ready() && (action == PM_RESTORE_PREPARE ||
  759. (action == PM_POST_SUSPEND && !IS_ENABLED(CONFIG_PM_AUTOSLEEP) &&
  760. !IS_ENABLED(CONFIG_PM_USERSPACE_AUTOSLEEP)))) {
  761. crng_reseed(NULL);
  762. pr_notice("crng reseeded on system resumption\n");
  763. }
  764. return 0;
  765. }
  766. static struct notifier_block pm_notifier = { .notifier_call = random_pm_notification };
  767. /*
  768. * This is called extremely early, before time keeping functionality is
  769. * available, but arch randomness is. Interrupts are not yet enabled.
  770. */
  771. void __init random_init_early(const char *command_line)
  772. {
  773. unsigned long entropy[BLAKE2S_BLOCK_SIZE / sizeof(long)];
  774. size_t i, longs, arch_bits;
  775. #if defined(LATENT_ENTROPY_PLUGIN)
  776. static const u8 compiletime_seed[BLAKE2S_BLOCK_SIZE] __initconst __latent_entropy;
  777. _mix_pool_bytes(compiletime_seed, sizeof(compiletime_seed));
  778. #endif
  779. for (i = 0, arch_bits = sizeof(entropy) * 8; i < ARRAY_SIZE(entropy);) {
  780. longs = arch_get_random_seed_longs(entropy, ARRAY_SIZE(entropy) - i);
  781. if (longs) {
  782. _mix_pool_bytes(entropy, sizeof(*entropy) * longs);
  783. i += longs;
  784. continue;
  785. }
  786. longs = arch_get_random_longs(entropy, ARRAY_SIZE(entropy) - i);
  787. if (longs) {
  788. _mix_pool_bytes(entropy, sizeof(*entropy) * longs);
  789. i += longs;
  790. continue;
  791. }
  792. arch_bits -= sizeof(*entropy) * 8;
  793. ++i;
  794. }
  795. _mix_pool_bytes(init_utsname(), sizeof(*(init_utsname())));
  796. _mix_pool_bytes(command_line, strlen(command_line));
  797. /* Reseed if already seeded by earlier phases. */
  798. if (crng_ready())
  799. crng_reseed(NULL);
  800. else if (trust_cpu)
  801. _credit_init_bits(arch_bits);
  802. }
  803. /*
  804. * This is called a little bit after the prior function, and now there is
  805. * access to timestamps counters. Interrupts are not yet enabled.
  806. */
  807. void __init random_init(void)
  808. {
  809. unsigned long entropy = random_get_entropy();
  810. ktime_t now = ktime_get_real();
  811. _mix_pool_bytes(&now, sizeof(now));
  812. _mix_pool_bytes(&entropy, sizeof(entropy));
  813. add_latent_entropy();
  814. /*
  815. * If we were initialized by the cpu or bootloader before workqueues
  816. * are initialized, then we should enable the static branch here.
  817. */
  818. if (!static_branch_likely(&crng_is_ready) && crng_init >= CRNG_READY)
  819. crng_set_ready(NULL);
  820. /* Reseed if already seeded by earlier phases. */
  821. if (crng_ready())
  822. crng_reseed(NULL);
  823. WARN_ON(register_pm_notifier(&pm_notifier));
  824. WARN(!entropy, "Missing cycle counter and fallback timer; RNG "
  825. "entropy collection will consequently suffer.");
  826. }
  827. /*
  828. * Add device- or boot-specific data to the input pool to help
  829. * initialize it.
  830. *
  831. * None of this adds any entropy; it is meant to avoid the problem of
  832. * the entropy pool having similar initial state across largely
  833. * identical devices.
  834. */
  835. void add_device_randomness(const void *buf, size_t len)
  836. {
  837. unsigned long entropy = random_get_entropy();
  838. unsigned long flags;
  839. spin_lock_irqsave(&input_pool.lock, flags);
  840. _mix_pool_bytes(&entropy, sizeof(entropy));
  841. _mix_pool_bytes(buf, len);
  842. spin_unlock_irqrestore(&input_pool.lock, flags);
  843. }
  844. EXPORT_SYMBOL(add_device_randomness);
  845. /*
  846. * Interface for in-kernel drivers of true hardware RNGs. Those devices
  847. * may produce endless random bits, so this function will sleep for
  848. * some amount of time after, if the sleep_after parameter is true.
  849. */
  850. void add_hwgenerator_randomness(const void *buf, size_t len, size_t entropy, bool sleep_after)
  851. {
  852. mix_pool_bytes(buf, len);
  853. credit_init_bits(entropy);
  854. /*
  855. * Throttle writing to once every reseed interval, unless we're not yet
  856. * initialized or no entropy is credited.
  857. */
  858. if (sleep_after && !kthread_should_stop() && (crng_ready() || !entropy))
  859. schedule_timeout_interruptible(crng_reseed_interval());
  860. }
  861. EXPORT_SYMBOL_GPL(add_hwgenerator_randomness);
  862. /*
  863. * Handle random seed passed by bootloader, and credit it depending
  864. * on the command line option 'random.trust_bootloader'.
  865. */
  866. void __init add_bootloader_randomness(const void *buf, size_t len)
  867. {
  868. mix_pool_bytes(buf, len);
  869. if (trust_bootloader)
  870. credit_init_bits(len * 8);
  871. }
  872. #if IS_ENABLED(CONFIG_VMGENID)
  873. static BLOCKING_NOTIFIER_HEAD(vmfork_chain);
  874. /*
  875. * Handle a new unique VM ID, which is unique, not secret, so we
  876. * don't credit it, but we do immediately force a reseed after so
  877. * that it's used by the crng posthaste.
  878. */
  879. void __cold add_vmfork_randomness(const void *unique_vm_id, size_t len)
  880. {
  881. add_device_randomness(unique_vm_id, len);
  882. if (crng_ready()) {
  883. crng_reseed(NULL);
  884. pr_notice("crng reseeded due to virtual machine fork\n");
  885. }
  886. blocking_notifier_call_chain(&vmfork_chain, 0, NULL);
  887. }
  888. #if IS_MODULE(CONFIG_VMGENID)
  889. EXPORT_SYMBOL_GPL(add_vmfork_randomness);
  890. #endif
  891. int __cold register_random_vmfork_notifier(struct notifier_block *nb)
  892. {
  893. return blocking_notifier_chain_register(&vmfork_chain, nb);
  894. }
  895. EXPORT_SYMBOL_GPL(register_random_vmfork_notifier);
  896. int __cold unregister_random_vmfork_notifier(struct notifier_block *nb)
  897. {
  898. return blocking_notifier_chain_unregister(&vmfork_chain, nb);
  899. }
  900. EXPORT_SYMBOL_GPL(unregister_random_vmfork_notifier);
  901. #endif
  902. struct fast_pool {
  903. unsigned long pool[4];
  904. unsigned long last;
  905. unsigned int count;
  906. struct timer_list mix;
  907. };
  908. static void mix_interrupt_randomness(struct timer_list *work);
  909. static DEFINE_PER_CPU(struct fast_pool, irq_randomness) = {
  910. #ifdef CONFIG_64BIT
  911. #define FASTMIX_PERM SIPHASH_PERMUTATION
  912. .pool = { SIPHASH_CONST_0, SIPHASH_CONST_1, SIPHASH_CONST_2, SIPHASH_CONST_3 },
  913. #else
  914. #define FASTMIX_PERM HSIPHASH_PERMUTATION
  915. .pool = { HSIPHASH_CONST_0, HSIPHASH_CONST_1, HSIPHASH_CONST_2, HSIPHASH_CONST_3 },
  916. #endif
  917. .mix = __TIMER_INITIALIZER(mix_interrupt_randomness, 0)
  918. };
  919. /*
  920. * This is [Half]SipHash-1-x, starting from an empty key. Because
  921. * the key is fixed, it assumes that its inputs are non-malicious,
  922. * and therefore this has no security on its own. s represents the
  923. * four-word SipHash state, while v represents a two-word input.
  924. */
  925. static void fast_mix(unsigned long s[4], unsigned long v1, unsigned long v2)
  926. {
  927. s[3] ^= v1;
  928. FASTMIX_PERM(s[0], s[1], s[2], s[3]);
  929. s[0] ^= v1;
  930. s[3] ^= v2;
  931. FASTMIX_PERM(s[0], s[1], s[2], s[3]);
  932. s[0] ^= v2;
  933. }
  934. #ifdef CONFIG_SMP
  935. /*
  936. * This function is called when the CPU has just come online, with
  937. * entry CPUHP_AP_RANDOM_ONLINE, just after CPUHP_AP_WORKQUEUE_ONLINE.
  938. */
  939. int __cold random_online_cpu(unsigned int cpu)
  940. {
  941. /*
  942. * During CPU shutdown and before CPU onlining, add_interrupt_
  943. * randomness() may schedule mix_interrupt_randomness(), and
  944. * set the MIX_INFLIGHT flag. However, because the worker can
  945. * be scheduled on a different CPU during this period, that
  946. * flag will never be cleared. For that reason, we zero out
  947. * the flag here, which runs just after workqueues are onlined
  948. * for the CPU again. This also has the effect of setting the
  949. * irq randomness count to zero so that new accumulated irqs
  950. * are fresh.
  951. */
  952. per_cpu_ptr(&irq_randomness, cpu)->count = 0;
  953. return 0;
  954. }
  955. #endif
  956. static void mix_interrupt_randomness(struct timer_list *work)
  957. {
  958. struct fast_pool *fast_pool = container_of(work, struct fast_pool, mix);
  959. /*
  960. * The size of the copied stack pool is explicitly 2 longs so that we
  961. * only ever ingest half of the siphash output each time, retaining
  962. * the other half as the next "key" that carries over. The entropy is
  963. * supposed to be sufficiently dispersed between bits so on average
  964. * we don't wind up "losing" some.
  965. */
  966. unsigned long pool[2];
  967. unsigned int count;
  968. /* Check to see if we're running on the wrong CPU due to hotplug. */
  969. local_irq_disable();
  970. if (fast_pool != this_cpu_ptr(&irq_randomness)) {
  971. local_irq_enable();
  972. return;
  973. }
  974. /*
  975. * Copy the pool to the stack so that the mixer always has a
  976. * consistent view, before we reenable irqs again.
  977. */
  978. memcpy(pool, fast_pool->pool, sizeof(pool));
  979. count = fast_pool->count;
  980. fast_pool->count = 0;
  981. fast_pool->last = jiffies;
  982. local_irq_enable();
  983. mix_pool_bytes(pool, sizeof(pool));
  984. credit_init_bits(clamp_t(unsigned int, (count & U16_MAX) / 64, 1, sizeof(pool) * 8));
  985. memzero_explicit(pool, sizeof(pool));
  986. }
  987. void add_interrupt_randomness(int irq)
  988. {
  989. enum { MIX_INFLIGHT = 1U << 31 };
  990. unsigned long entropy = random_get_entropy();
  991. struct fast_pool *fast_pool = this_cpu_ptr(&irq_randomness);
  992. struct pt_regs *regs = get_irq_regs();
  993. unsigned int new_count;
  994. fast_mix(fast_pool->pool, entropy,
  995. (regs ? instruction_pointer(regs) : _RET_IP_) ^ swab(irq));
  996. new_count = ++fast_pool->count;
  997. if (new_count & MIX_INFLIGHT)
  998. return;
  999. if (new_count < 1024 && !time_is_before_jiffies(fast_pool->last + HZ))
  1000. return;
  1001. fast_pool->count |= MIX_INFLIGHT;
  1002. if (!timer_pending(&fast_pool->mix)) {
  1003. fast_pool->mix.expires = jiffies;
  1004. add_timer_on(&fast_pool->mix, raw_smp_processor_id());
  1005. }
  1006. }
  1007. EXPORT_SYMBOL_GPL(add_interrupt_randomness);
  1008. /* There is one of these per entropy source */
  1009. struct timer_rand_state {
  1010. unsigned long last_time;
  1011. long last_delta, last_delta2;
  1012. };
  1013. /*
  1014. * This function adds entropy to the entropy "pool" by using timing
  1015. * delays. It uses the timer_rand_state structure to make an estimate
  1016. * of how many bits of entropy this call has added to the pool. The
  1017. * value "num" is also added to the pool; it should somehow describe
  1018. * the type of event that just happened.
  1019. */
  1020. static void add_timer_randomness(struct timer_rand_state *state, unsigned int num)
  1021. {
  1022. unsigned long entropy = random_get_entropy(), now = jiffies, flags;
  1023. long delta, delta2, delta3;
  1024. unsigned int bits;
  1025. /*
  1026. * If we're in a hard IRQ, add_interrupt_randomness() will be called
  1027. * sometime after, so mix into the fast pool.
  1028. */
  1029. if (in_hardirq()) {
  1030. fast_mix(this_cpu_ptr(&irq_randomness)->pool, entropy, num);
  1031. } else {
  1032. spin_lock_irqsave(&input_pool.lock, flags);
  1033. _mix_pool_bytes(&entropy, sizeof(entropy));
  1034. _mix_pool_bytes(&num, sizeof(num));
  1035. spin_unlock_irqrestore(&input_pool.lock, flags);
  1036. }
  1037. if (crng_ready())
  1038. return;
  1039. /*
  1040. * Calculate number of bits of randomness we probably added.
  1041. * We take into account the first, second and third-order deltas
  1042. * in order to make our estimate.
  1043. */
  1044. delta = now - READ_ONCE(state->last_time);
  1045. WRITE_ONCE(state->last_time, now);
  1046. delta2 = delta - READ_ONCE(state->last_delta);
  1047. WRITE_ONCE(state->last_delta, delta);
  1048. delta3 = delta2 - READ_ONCE(state->last_delta2);
  1049. WRITE_ONCE(state->last_delta2, delta2);
  1050. if (delta < 0)
  1051. delta = -delta;
  1052. if (delta2 < 0)
  1053. delta2 = -delta2;
  1054. if (delta3 < 0)
  1055. delta3 = -delta3;
  1056. if (delta > delta2)
  1057. delta = delta2;
  1058. if (delta > delta3)
  1059. delta = delta3;
  1060. /*
  1061. * delta is now minimum absolute delta. Round down by 1 bit
  1062. * on general principles, and limit entropy estimate to 11 bits.
  1063. */
  1064. bits = min(fls(delta >> 1), 11);
  1065. /*
  1066. * As mentioned above, if we're in a hard IRQ, add_interrupt_randomness()
  1067. * will run after this, which uses a different crediting scheme of 1 bit
  1068. * per every 64 interrupts. In order to let that function do accounting
  1069. * close to the one in this function, we credit a full 64/64 bit per bit,
  1070. * and then subtract one to account for the extra one added.
  1071. */
  1072. if (in_hardirq())
  1073. this_cpu_ptr(&irq_randomness)->count += max(1u, bits * 64) - 1;
  1074. else
  1075. _credit_init_bits(bits);
  1076. }
  1077. void add_input_randomness(unsigned int type, unsigned int code, unsigned int value)
  1078. {
  1079. static unsigned char last_value;
  1080. static struct timer_rand_state input_timer_state = { INITIAL_JIFFIES };
  1081. /* Ignore autorepeat and the like. */
  1082. if (value == last_value)
  1083. return;
  1084. last_value = value;
  1085. add_timer_randomness(&input_timer_state,
  1086. (type << 4) ^ code ^ (code >> 4) ^ value);
  1087. }
  1088. EXPORT_SYMBOL_GPL(add_input_randomness);
  1089. #ifdef CONFIG_BLOCK
  1090. void add_disk_randomness(struct gendisk *disk)
  1091. {
  1092. if (!disk || !disk->random)
  1093. return;
  1094. /* First major is 1, so we get >= 0x200 here. */
  1095. add_timer_randomness(disk->random, 0x100 + disk_devt(disk));
  1096. }
  1097. EXPORT_SYMBOL_GPL(add_disk_randomness);
  1098. void __cold rand_initialize_disk(struct gendisk *disk)
  1099. {
  1100. struct timer_rand_state *state;
  1101. /*
  1102. * If kzalloc returns null, we just won't use that entropy
  1103. * source.
  1104. */
  1105. state = kzalloc_obj(struct timer_rand_state);
  1106. if (state) {
  1107. state->last_time = INITIAL_JIFFIES;
  1108. disk->random = state;
  1109. }
  1110. }
  1111. #endif
  1112. struct entropy_timer_state {
  1113. unsigned long entropy;
  1114. struct timer_list timer;
  1115. atomic_t samples;
  1116. unsigned int samples_per_bit;
  1117. };
  1118. /*
  1119. * Each time the timer fires, we expect that we got an unpredictable jump in
  1120. * the cycle counter. Even if the timer is running on another CPU, the timer
  1121. * activity will be touching the stack of the CPU that is generating entropy.
  1122. *
  1123. * Note that we don't re-arm the timer in the timer itself - we are happy to be
  1124. * scheduled away, since that just makes the load more complex, but we do not
  1125. * want the timer to keep ticking unless the entropy loop is running.
  1126. *
  1127. * So the re-arming always happens in the entropy loop itself.
  1128. */
  1129. static void __cold entropy_timer(struct timer_list *timer)
  1130. {
  1131. struct entropy_timer_state *state = container_of(timer, struct entropy_timer_state, timer);
  1132. unsigned long entropy = random_get_entropy();
  1133. mix_pool_bytes(&entropy, sizeof(entropy));
  1134. if (atomic_inc_return(&state->samples) % state->samples_per_bit == 0)
  1135. credit_init_bits(1);
  1136. }
  1137. /*
  1138. * If we have an actual cycle counter, see if we can generate enough entropy
  1139. * with timing noise.
  1140. */
  1141. static void __cold try_to_generate_entropy(void)
  1142. {
  1143. enum { NUM_TRIAL_SAMPLES = 8192, MAX_SAMPLES_PER_BIT = HZ / 15 };
  1144. u8 stack_bytes[sizeof(struct entropy_timer_state) + SMP_CACHE_BYTES - 1];
  1145. struct entropy_timer_state *stack = PTR_ALIGN((void *)stack_bytes, SMP_CACHE_BYTES);
  1146. unsigned int i, num_different = 0;
  1147. unsigned long last = random_get_entropy();
  1148. cpumask_var_t timer_cpus;
  1149. int cpu = -1;
  1150. for (i = 0; i < NUM_TRIAL_SAMPLES - 1; ++i) {
  1151. stack->entropy = random_get_entropy();
  1152. if (stack->entropy != last)
  1153. ++num_different;
  1154. last = stack->entropy;
  1155. }
  1156. stack->samples_per_bit = DIV_ROUND_UP(NUM_TRIAL_SAMPLES, num_different + 1);
  1157. if (stack->samples_per_bit > MAX_SAMPLES_PER_BIT)
  1158. return;
  1159. atomic_set(&stack->samples, 0);
  1160. timer_setup_on_stack(&stack->timer, entropy_timer, 0);
  1161. if (!alloc_cpumask_var(&timer_cpus, GFP_KERNEL))
  1162. goto out;
  1163. while (!crng_ready() && !signal_pending(current)) {
  1164. /*
  1165. * Check !timer_pending() and then ensure that any previous callback has finished
  1166. * executing by checking timer_delete_sync_try(), before queueing the next one.
  1167. */
  1168. if (!timer_pending(&stack->timer) && timer_delete_sync_try(&stack->timer) >= 0) {
  1169. unsigned int num_cpus;
  1170. /*
  1171. * Preemption must be disabled here, both to read the current CPU number
  1172. * and to avoid scheduling a timer on a dead CPU.
  1173. */
  1174. preempt_disable();
  1175. /* Only schedule callbacks on timer CPUs that are online. */
  1176. cpumask_and(timer_cpus, housekeeping_cpumask(HK_TYPE_TIMER), cpu_online_mask);
  1177. num_cpus = cpumask_weight(timer_cpus);
  1178. /* In very bizarre case of misconfiguration, fallback to all online. */
  1179. if (unlikely(num_cpus == 0)) {
  1180. *timer_cpus = *cpu_online_mask;
  1181. num_cpus = cpumask_weight(timer_cpus);
  1182. }
  1183. /* Basic CPU round-robin, which avoids the current CPU. */
  1184. do {
  1185. cpu = cpumask_next(cpu, timer_cpus);
  1186. if (cpu >= nr_cpu_ids)
  1187. cpu = cpumask_first(timer_cpus);
  1188. } while (cpu == smp_processor_id() && num_cpus > 1);
  1189. /* Expiring the timer at `jiffies` means it's the next tick. */
  1190. stack->timer.expires = jiffies;
  1191. add_timer_on(&stack->timer, cpu);
  1192. preempt_enable();
  1193. }
  1194. mix_pool_bytes(&stack->entropy, sizeof(stack->entropy));
  1195. schedule();
  1196. stack->entropy = random_get_entropy();
  1197. }
  1198. mix_pool_bytes(&stack->entropy, sizeof(stack->entropy));
  1199. free_cpumask_var(timer_cpus);
  1200. out:
  1201. timer_delete_sync(&stack->timer);
  1202. timer_destroy_on_stack(&stack->timer);
  1203. }
  1204. /**********************************************************************
  1205. *
  1206. * Userspace reader/writer interfaces.
  1207. *
  1208. * getrandom(2) is the primary modern interface into the RNG and should
  1209. * be used in preference to anything else.
  1210. *
  1211. * Reading from /dev/random has the same functionality as calling
  1212. * getrandom(2) with flags=0. In earlier versions, however, it had
  1213. * vastly different semantics and should therefore be avoided, to
  1214. * prevent backwards compatibility issues.
  1215. *
  1216. * Reading from /dev/urandom has the same functionality as calling
  1217. * getrandom(2) with flags=GRND_INSECURE. Because it does not block
  1218. * waiting for the RNG to be ready, it should not be used.
  1219. *
  1220. * Writing to either /dev/random or /dev/urandom adds entropy to
  1221. * the input pool but does not credit it.
  1222. *
  1223. * Polling on /dev/random indicates when the RNG is initialized, on
  1224. * the read side, and when it wants new entropy, on the write side.
  1225. *
  1226. * Both /dev/random and /dev/urandom have the same set of ioctls for
  1227. * adding entropy, getting the entropy count, zeroing the count, and
  1228. * reseeding the crng.
  1229. *
  1230. **********************************************************************/
  1231. SYSCALL_DEFINE3(getrandom, char __user *, ubuf, size_t, len, unsigned int, flags)
  1232. {
  1233. struct iov_iter iter;
  1234. int ret;
  1235. if (flags & ~(GRND_NONBLOCK | GRND_RANDOM | GRND_INSECURE))
  1236. return -EINVAL;
  1237. /*
  1238. * Requesting insecure and blocking randomness at the same time makes
  1239. * no sense.
  1240. */
  1241. if ((flags & (GRND_INSECURE | GRND_RANDOM)) == (GRND_INSECURE | GRND_RANDOM))
  1242. return -EINVAL;
  1243. if (!crng_ready() && !(flags & GRND_INSECURE)) {
  1244. if (flags & GRND_NONBLOCK)
  1245. return -EAGAIN;
  1246. ret = wait_for_random_bytes();
  1247. if (unlikely(ret))
  1248. return ret;
  1249. }
  1250. ret = import_ubuf(ITER_DEST, ubuf, len, &iter);
  1251. if (unlikely(ret))
  1252. return ret;
  1253. return get_random_bytes_user(&iter);
  1254. }
  1255. static __poll_t random_poll(struct file *file, poll_table *wait)
  1256. {
  1257. poll_wait(file, &crng_init_wait, wait);
  1258. return crng_ready() ? EPOLLIN | EPOLLRDNORM : EPOLLOUT | EPOLLWRNORM;
  1259. }
  1260. static ssize_t write_pool_user(struct iov_iter *iter)
  1261. {
  1262. u8 block[BLAKE2S_BLOCK_SIZE];
  1263. ssize_t ret = 0;
  1264. size_t copied;
  1265. if (unlikely(!iov_iter_count(iter)))
  1266. return 0;
  1267. for (;;) {
  1268. copied = copy_from_iter(block, sizeof(block), iter);
  1269. ret += copied;
  1270. mix_pool_bytes(block, copied);
  1271. if (!iov_iter_count(iter) || copied != sizeof(block))
  1272. break;
  1273. BUILD_BUG_ON(PAGE_SIZE % sizeof(block) != 0);
  1274. if (ret % PAGE_SIZE == 0) {
  1275. if (signal_pending(current))
  1276. break;
  1277. cond_resched();
  1278. }
  1279. }
  1280. memzero_explicit(block, sizeof(block));
  1281. return ret ? ret : -EFAULT;
  1282. }
  1283. static ssize_t random_write_iter(struct kiocb *kiocb, struct iov_iter *iter)
  1284. {
  1285. return write_pool_user(iter);
  1286. }
  1287. static ssize_t urandom_read_iter(struct kiocb *kiocb, struct iov_iter *iter)
  1288. {
  1289. static int maxwarn = 10;
  1290. /*
  1291. * Opportunistically attempt to initialize the RNG on platforms that
  1292. * have fast cycle counters, but don't (for now) require it to succeed.
  1293. */
  1294. if (!crng_ready())
  1295. try_to_generate_entropy();
  1296. if (!crng_ready()) {
  1297. if (!ratelimit_disable && maxwarn <= 0)
  1298. ratelimit_state_inc_miss(&urandom_warning);
  1299. else if (ratelimit_disable || __ratelimit(&urandom_warning)) {
  1300. --maxwarn;
  1301. pr_notice("%s: uninitialized urandom read (%zu bytes read)\n",
  1302. current->comm, iov_iter_count(iter));
  1303. }
  1304. }
  1305. return get_random_bytes_user(iter);
  1306. }
  1307. static ssize_t random_read_iter(struct kiocb *kiocb, struct iov_iter *iter)
  1308. {
  1309. int ret;
  1310. if (!crng_ready() &&
  1311. ((kiocb->ki_flags & (IOCB_NOWAIT | IOCB_NOIO)) ||
  1312. (kiocb->ki_filp->f_flags & O_NONBLOCK)))
  1313. return -EAGAIN;
  1314. ret = wait_for_random_bytes();
  1315. if (ret != 0)
  1316. return ret;
  1317. return get_random_bytes_user(iter);
  1318. }
  1319. static long random_ioctl(struct file *f, unsigned int cmd, unsigned long arg)
  1320. {
  1321. int __user *p = (int __user *)arg;
  1322. int ent_count;
  1323. switch (cmd) {
  1324. case RNDGETENTCNT:
  1325. /* Inherently racy, no point locking. */
  1326. if (put_user(input_pool.init_bits, p))
  1327. return -EFAULT;
  1328. return 0;
  1329. case RNDADDTOENTCNT:
  1330. if (!capable(CAP_SYS_ADMIN))
  1331. return -EPERM;
  1332. if (get_user(ent_count, p))
  1333. return -EFAULT;
  1334. if (ent_count < 0)
  1335. return -EINVAL;
  1336. credit_init_bits(ent_count);
  1337. return 0;
  1338. case RNDADDENTROPY: {
  1339. struct iov_iter iter;
  1340. ssize_t ret;
  1341. int len;
  1342. if (!capable(CAP_SYS_ADMIN))
  1343. return -EPERM;
  1344. if (get_user(ent_count, p++))
  1345. return -EFAULT;
  1346. if (ent_count < 0)
  1347. return -EINVAL;
  1348. if (get_user(len, p++))
  1349. return -EFAULT;
  1350. ret = import_ubuf(ITER_SOURCE, p, len, &iter);
  1351. if (unlikely(ret))
  1352. return ret;
  1353. ret = write_pool_user(&iter);
  1354. if (unlikely(ret < 0))
  1355. return ret;
  1356. /* Since we're crediting, enforce that it was all written into the pool. */
  1357. if (unlikely(ret != len))
  1358. return -EFAULT;
  1359. credit_init_bits(ent_count);
  1360. return 0;
  1361. }
  1362. case RNDZAPENTCNT:
  1363. case RNDCLEARPOOL:
  1364. /* No longer has any effect. */
  1365. if (!capable(CAP_SYS_ADMIN))
  1366. return -EPERM;
  1367. return 0;
  1368. case RNDRESEEDCRNG:
  1369. if (!capable(CAP_SYS_ADMIN))
  1370. return -EPERM;
  1371. if (!crng_ready())
  1372. return -ENODATA;
  1373. crng_reseed(NULL);
  1374. return 0;
  1375. default:
  1376. return -EINVAL;
  1377. }
  1378. }
  1379. static int random_fasync(int fd, struct file *filp, int on)
  1380. {
  1381. return fasync_helper(fd, filp, on, &fasync);
  1382. }
  1383. const struct file_operations random_fops = {
  1384. .read_iter = random_read_iter,
  1385. .write_iter = random_write_iter,
  1386. .poll = random_poll,
  1387. .unlocked_ioctl = random_ioctl,
  1388. .compat_ioctl = compat_ptr_ioctl,
  1389. .fasync = random_fasync,
  1390. .llseek = noop_llseek,
  1391. .splice_read = copy_splice_read,
  1392. .splice_write = iter_file_splice_write,
  1393. };
  1394. const struct file_operations urandom_fops = {
  1395. .read_iter = urandom_read_iter,
  1396. .write_iter = random_write_iter,
  1397. .unlocked_ioctl = random_ioctl,
  1398. .compat_ioctl = compat_ptr_ioctl,
  1399. .fasync = random_fasync,
  1400. .llseek = noop_llseek,
  1401. .splice_read = copy_splice_read,
  1402. .splice_write = iter_file_splice_write,
  1403. };
  1404. /********************************************************************
  1405. *
  1406. * Sysctl interface.
  1407. *
  1408. * These are partly unused legacy knobs with dummy values to not break
  1409. * userspace and partly still useful things. They are usually accessible
  1410. * in /proc/sys/kernel/random/ and are as follows:
  1411. *
  1412. * - boot_id - a UUID representing the current boot.
  1413. *
  1414. * - uuid - a random UUID, different each time the file is read.
  1415. *
  1416. * - poolsize - the number of bits of entropy that the input pool can
  1417. * hold, tied to the POOL_BITS constant.
  1418. *
  1419. * - entropy_avail - the number of bits of entropy currently in the
  1420. * input pool. Always <= poolsize.
  1421. *
  1422. * - write_wakeup_threshold - the amount of entropy in the input pool
  1423. * below which write polls to /dev/random will unblock, requesting
  1424. * more entropy, tied to the POOL_READY_BITS constant. It is writable
  1425. * to avoid breaking old userspaces, but writing to it does not
  1426. * change any behavior of the RNG.
  1427. *
  1428. * - urandom_min_reseed_secs - fixed to the value CRNG_RESEED_INTERVAL.
  1429. * It is writable to avoid breaking old userspaces, but writing
  1430. * to it does not change any behavior of the RNG.
  1431. *
  1432. ********************************************************************/
  1433. #ifdef CONFIG_SYSCTL
  1434. #include <linux/sysctl.h>
  1435. static int sysctl_random_min_urandom_seed = CRNG_RESEED_INTERVAL / HZ;
  1436. static int sysctl_random_write_wakeup_bits = POOL_READY_BITS;
  1437. static int sysctl_poolsize = POOL_BITS;
  1438. static u8 sysctl_bootid[UUID_SIZE];
  1439. /*
  1440. * This function is used to return both the bootid UUID, and random
  1441. * UUID. The difference is in whether table->data is NULL; if it is,
  1442. * then a new UUID is generated and returned to the user.
  1443. */
  1444. static int proc_do_uuid(const struct ctl_table *table, int write, void *buf,
  1445. size_t *lenp, loff_t *ppos)
  1446. {
  1447. u8 tmp_uuid[UUID_SIZE], *uuid;
  1448. char uuid_string[UUID_STRING_LEN + 1];
  1449. struct ctl_table fake_table = {
  1450. .data = uuid_string,
  1451. .maxlen = UUID_STRING_LEN
  1452. };
  1453. if (write)
  1454. return -EPERM;
  1455. uuid = table->data;
  1456. if (!uuid) {
  1457. uuid = tmp_uuid;
  1458. generate_random_uuid(uuid);
  1459. } else {
  1460. static DEFINE_SPINLOCK(bootid_spinlock);
  1461. spin_lock(&bootid_spinlock);
  1462. if (!uuid[8])
  1463. generate_random_uuid(uuid);
  1464. spin_unlock(&bootid_spinlock);
  1465. }
  1466. snprintf(uuid_string, sizeof(uuid_string), "%pU", uuid);
  1467. return proc_dostring(&fake_table, 0, buf, lenp, ppos);
  1468. }
  1469. /* The same as proc_dointvec, but writes don't change anything. */
  1470. static int proc_do_rointvec(const struct ctl_table *table, int write, void *buf,
  1471. size_t *lenp, loff_t *ppos)
  1472. {
  1473. return write ? 0 : proc_dointvec(table, 0, buf, lenp, ppos);
  1474. }
  1475. static const struct ctl_table random_table[] = {
  1476. {
  1477. .procname = "poolsize",
  1478. .data = &sysctl_poolsize,
  1479. .maxlen = sizeof(int),
  1480. .mode = 0444,
  1481. .proc_handler = proc_dointvec,
  1482. },
  1483. {
  1484. .procname = "entropy_avail",
  1485. .data = &input_pool.init_bits,
  1486. .maxlen = sizeof(int),
  1487. .mode = 0444,
  1488. .proc_handler = proc_dointvec,
  1489. },
  1490. {
  1491. .procname = "write_wakeup_threshold",
  1492. .data = &sysctl_random_write_wakeup_bits,
  1493. .maxlen = sizeof(int),
  1494. .mode = 0644,
  1495. .proc_handler = proc_do_rointvec,
  1496. },
  1497. {
  1498. .procname = "urandom_min_reseed_secs",
  1499. .data = &sysctl_random_min_urandom_seed,
  1500. .maxlen = sizeof(int),
  1501. .mode = 0644,
  1502. .proc_handler = proc_do_rointvec,
  1503. },
  1504. {
  1505. .procname = "boot_id",
  1506. .data = &sysctl_bootid,
  1507. .mode = 0444,
  1508. .proc_handler = proc_do_uuid,
  1509. },
  1510. {
  1511. .procname = "uuid",
  1512. .mode = 0444,
  1513. .proc_handler = proc_do_uuid,
  1514. },
  1515. };
  1516. /*
  1517. * random_init() is called before sysctl_init(),
  1518. * so we cannot call register_sysctl_init() in random_init()
  1519. */
  1520. static int __init random_sysctls_init(void)
  1521. {
  1522. register_sysctl_init("kernel/random", random_table);
  1523. return 0;
  1524. }
  1525. device_initcall(random_sysctls_init);
  1526. #endif