From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: torvalds@linux-foundation.org, akpm@linux-foundation.org,
alan@lxorguk.ukuu.org.uk, Theodore Tso <tytso@mit.edu>,
Eric Wustrow <ewust@umich.edu>,
Nadia Heninger <nadiah@cs.ucsd.edu>,
Zakir Durumeric <zakir@umich.edu>,
"J. Alex Halderman" <jhalderm@umich.edu>
Subject: [ 14/70] random: make add_interrupt_randomness() do something sane
Date: Tue, 07 Aug 2012 04:28:09 +0100 [thread overview]
Message-ID: <20120807032758.126541115@decadent.org.uk> (raw)
In-Reply-To: <20120807032755.803571133@decadent.org.uk>
3.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Theodore Ts'o <tytso@mit.edu>
commit 775f4b297b780601e61787b766f306ed3e1d23eb upstream.
We've been moving away from add_interrupt_randomness() for various
reasons: it's too expensive to do on every interrupt, and flooding the
CPU with interrupts could theoretically cause bogus floods of entropy
from a somewhat externally controllable source.
This solves both problems by limiting the actual randomness addition
to just once a second or after 64 interrupts, whicever comes first.
During that time, the interrupt cycle data is buffered up in a per-cpu
pool. Also, we make sure the the nonblocking pool used by urandom is
initialized before we start feeding the normal input pool. This
assures that /dev/urandom is returning unpredictable data as soon as
possible.
(Based on an original patch by Linus, but significantly modified by
tytso.)
Tested-by: Eric Wustrow <ewust@umich.edu>
Reported-by: Eric Wustrow <ewust@umich.edu>
Reported-by: Nadia Heninger <nadiah@cs.ucsd.edu>
Reported-by: Zakir Durumeric <zakir@umich.edu>
Reported-by: J. Alex Halderman <jhalderm@umich.edu>.
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: "Theodore Ts'o" <tytso@mit.edu>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
drivers/char/random.c | 103 +++++++++++++++++++++++++++++++++++++--------
drivers/mfd/ab3100-core.c | 2 -
include/linux/random.h | 2 +-
kernel/irq/handle.c | 7 ++-
4 files changed, 90 insertions(+), 24 deletions(-)
diff --git a/drivers/char/random.c b/drivers/char/random.c
index cb541b9..9fcceac 100644
--- a/drivers/char/random.c
+++ b/drivers/char/random.c
@@ -127,19 +127,15 @@
*
* void add_input_randomness(unsigned int type, unsigned int code,
* unsigned int value);
- * void add_interrupt_randomness(int irq);
+ * void add_interrupt_randomness(int irq, int irq_flags);
* void add_disk_randomness(struct gendisk *disk);
*
* add_input_randomness() uses the input layer interrupt timing, as well as
* the event type information from the hardware.
*
- * add_interrupt_randomness() uses the inter-interrupt timing as random
- * inputs to the entropy pool. Note that not all interrupts are good
- * sources of randomness! For example, the timer interrupts is not a
- * good choice, because the periodicity of the interrupts is too
- * regular, and hence predictable to an attacker. Network Interface
- * Controller interrupts are a better measure, since the timing of the
- * NIC interrupts are more unpredictable.
+ * add_interrupt_randomness() uses the interrupt timing as random
+ * inputs to the entropy pool. Using the cycle counters and the irq source
+ * as inputs, it feeds the randomness roughly once a second.
*
* add_disk_randomness() uses what amounts to the seek time of block
* layer request events, on a per-disk_devt basis, as input to the
@@ -248,6 +244,7 @@
#include <linux/percpu.h>
#include <linux/cryptohash.h>
#include <linux/fips.h>
+#include <linux/ptrace.h>
#ifdef CONFIG_GENERIC_HARDIRQS
# include <linux/irq.h>
@@ -256,6 +253,7 @@
#include <asm/processor.h>
#include <asm/uaccess.h>
#include <asm/irq.h>
+#include <asm/irq_regs.h>
#include <asm/io.h>
/*
@@ -421,7 +419,9 @@ struct entropy_store {
spinlock_t lock;
unsigned add_ptr;
int entropy_count;
+ int entropy_total;
int input_rotate;
+ unsigned int initialized:1;
__u8 last_data[EXTRACT_SIZE];
};
@@ -454,6 +454,10 @@ static struct entropy_store nonblocking_pool = {
.pool = nonblocking_pool_data
};
+static __u32 const twist_table[8] = {
+ 0x00000000, 0x3b6e20c8, 0x76dc4190, 0x4db26158,
+ 0xedb88320, 0xd6d6a3e8, 0x9b64c2b0, 0xa00ae278 };
+
/*
* This function adds bytes into the entropy "pool". It does not
* update the entropy estimate. The caller should call
@@ -467,9 +471,6 @@ static struct entropy_store nonblocking_pool = {
static void mix_pool_bytes_extract(struct entropy_store *r, const void *in,
int nbytes, __u8 out[64])
{
- static __u32 const twist_table[8] = {
- 0x00000000, 0x3b6e20c8, 0x76dc4190, 0x4db26158,
- 0xedb88320, 0xd6d6a3e8, 0x9b64c2b0, 0xa00ae278 };
unsigned long i, j, tap1, tap2, tap3, tap4, tap5;
int input_rotate;
int wordmask = r->poolinfo->poolwords - 1;
@@ -528,6 +529,36 @@ static void mix_pool_bytes(struct entropy_store *r, const void *in, int bytes)
mix_pool_bytes_extract(r, in, bytes, NULL);
}
+struct fast_pool {
+ __u32 pool[4];
+ unsigned long last;
+ unsigned short count;
+ unsigned char rotate;
+ unsigned char last_timer_intr;
+};
+
+/*
+ * This is a fast mixing routine used by the interrupt randomness
+ * collector. It's hardcoded for an 128 bit pool and assumes that any
+ * locks that might be needed are taken by the caller.
+ */
+static void fast_mix(struct fast_pool *f, const void *in, int nbytes)
+{
+ const char *bytes = in;
+ __u32 w;
+ unsigned i = f->count;
+ unsigned input_rotate = f->rotate;
+
+ while (nbytes--) {
+ w = rol32(*bytes++, input_rotate & 31) ^ f->pool[i & 3] ^
+ f->pool[(i + 1) & 3];
+ f->pool[i & 3] = (w >> 3) ^ twist_table[w & 7];
+ input_rotate += (i++ & 3) ? 7 : 14;
+ }
+ f->count = i;
+ f->rotate = input_rotate;
+}
+
/*
* Credit (or debit) the entropy store with n bits of entropy
*/
@@ -551,6 +582,12 @@ static void credit_entropy_bits(struct entropy_store *r, int nbits)
entropy_count = r->poolinfo->POOLBITS;
r->entropy_count = entropy_count;
+ if (!r->initialized && nbits > 0) {
+ r->entropy_total += nbits;
+ if (r->entropy_total > 128)
+ r->initialized = 1;
+ }
+
/* should we wake readers? */
if (r == &input_pool && entropy_count >= random_read_wakeup_thresh) {
wake_up_interruptible(&random_read_wait);
@@ -700,17 +737,48 @@ void add_input_randomness(unsigned int type, unsigned int code,
}
EXPORT_SYMBOL_GPL(add_input_randomness);
-void add_interrupt_randomness(int irq)
+static DEFINE_PER_CPU(struct fast_pool, irq_randomness);
+
+void add_interrupt_randomness(int irq, int irq_flags)
{
- struct timer_rand_state *state;
+ struct entropy_store *r;
+ struct fast_pool *fast_pool = &__get_cpu_var(irq_randomness);
+ struct pt_regs *regs = get_irq_regs();
+ unsigned long now = jiffies;
+ __u32 input[4], cycles = get_cycles();
+
+ input[0] = cycles ^ jiffies;
+ input[1] = irq;
+ if (regs) {
+ __u64 ip = instruction_pointer(regs);
+ input[2] = ip;
+ input[3] = ip >> 32;
+ }
- state = get_timer_rand_state(irq);
+ fast_mix(fast_pool, input, sizeof(input));
- if (state == NULL)
+ if ((fast_pool->count & 1023) &&
+ !time_after(now, fast_pool->last + HZ))
return;
- DEBUG_ENT("irq event %d\n", irq);
- add_timer_randomness(state, 0x100 + irq);
+ fast_pool->last = now;
+
+ r = nonblocking_pool.initialized ? &input_pool : &nonblocking_pool;
+ mix_pool_bytes(r, &fast_pool->pool, sizeof(fast_pool->pool));
+ /*
+ * If we don't have a valid cycle counter, and we see
+ * back-to-back timer interrupts, then skip giving credit for
+ * any entropy.
+ */
+ if (cycles == 0) {
+ if (irq_flags & __IRQF_TIMER) {
+ if (fast_pool->last_timer_intr)
+ return;
+ fast_pool->last_timer_intr = 1;
+ } else
+ fast_pool->last_timer_intr = 0;
+ }
+ credit_entropy_bits(r, 1);
}
#ifdef CONFIG_BLOCK
@@ -971,6 +1039,7 @@ static void init_std_data(struct entropy_store *r)
spin_lock_irqsave(&r->lock, flags);
r->entropy_count = 0;
+ r->entropy_total = 0;
spin_unlock_irqrestore(&r->lock, flags);
now = ktime_get_real();
diff --git a/drivers/mfd/ab3100-core.c b/drivers/mfd/ab3100-core.c
index 1efad20..9522d6b 100644
--- a/drivers/mfd/ab3100-core.c
+++ b/drivers/mfd/ab3100-core.c
@@ -409,8 +409,6 @@ static irqreturn_t ab3100_irq_handler(int irq, void *data)
u32 fatevent;
int err;
- add_interrupt_randomness(irq);
-
err = ab3100_get_register_page_interruptible(ab3100, AB3100_EVENTA1,
event_regs, 3);
if (err)
diff --git a/include/linux/random.h b/include/linux/random.h
index 8f74538..6ef39d7 100644
--- a/include/linux/random.h
+++ b/include/linux/random.h
@@ -52,7 +52,7 @@ extern void rand_initialize_irq(int irq);
extern void add_input_randomness(unsigned int type, unsigned int code,
unsigned int value);
-extern void add_interrupt_randomness(int irq);
+extern void add_interrupt_randomness(int irq, int irq_flags);
extern void get_random_bytes(void *buf, int nbytes);
void generate_random_uuid(unsigned char uuid_out[16]);
diff --git a/kernel/irq/handle.c b/kernel/irq/handle.c
index bdb1803..131ca17 100644
--- a/kernel/irq/handle.c
+++ b/kernel/irq/handle.c
@@ -133,7 +133,7 @@ irqreturn_t
handle_irq_event_percpu(struct irq_desc *desc, struct irqaction *action)
{
irqreturn_t retval = IRQ_NONE;
- unsigned int random = 0, irq = desc->irq_data.irq;
+ unsigned int flags = 0, irq = desc->irq_data.irq;
do {
irqreturn_t res;
@@ -161,7 +161,7 @@ handle_irq_event_percpu(struct irq_desc *desc, struct irqaction *action)
/* Fall through to add to randomness */
case IRQ_HANDLED:
- random |= action->flags;
+ flags |= action->flags;
break;
default:
@@ -172,8 +172,7 @@ handle_irq_event_percpu(struct irq_desc *desc, struct irqaction *action)
action = action->next;
} while (action);
- if (random & IRQF_SAMPLE_RANDOM)
- add_interrupt_randomness(irq);
+ add_interrupt_randomness(irq, flags);
if (!noirqdebug)
note_interrupt(irq, desc, retval);
next prev parent reply other threads:[~2012-08-07 3:38 UTC|newest]
Thread overview: 75+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-08-07 3:27 [ 00/70] 3.2.27-stable review Ben Hutchings
2012-08-07 3:27 ` [ 01/70] sched: Fix race in task_group() Ben Hutchings
2012-08-07 3:27 ` [ 02/70] floppy: Cleanup disk->queue before caling put_disk() if add_disk() was never called Ben Hutchings
2012-08-07 22:49 ` Herton Ronaldo Krzesinski
2012-08-08 0:40 ` Ben Hutchings
2012-08-08 13:02 ` Herton Ronaldo Krzesinski
2012-08-07 3:27 ` [ 03/70] xen: mark local pages as FOREIGN in the m2p_override Ben Hutchings
2012-08-07 3:27 ` [ 04/70] [media] lirc_sir: make device registration work Ben Hutchings
2012-08-07 3:28 ` [ 05/70] stable: update references to older 2.6 versions for 3.x Ben Hutchings
2012-08-07 3:28 ` [ 06/70] ALSA: hda - add dock support for Thinkpad X230 Tablet Ben Hutchings
2012-08-07 3:28 ` [ 07/70] cfg80211: fix interface combinations check for ADHOC(IBSS) Ben Hutchings
2012-08-07 3:28 ` [ 08/70] m68k: Correct the Atari ALLOWINT definition Ben Hutchings
2012-08-07 3:28 ` [ 09/70] [media] ene_ir: Fix driver initialisation Ben Hutchings
2012-08-07 3:28 ` [ 10/70] nfsd4: our filesystems are normally case sensitive Ben Hutchings
2012-08-07 3:28 ` [ 11/70] random: Use arch_get_random_int instead of cycle counter if avail Ben Hutchings
2012-08-07 3:28 ` [ 12/70] random: Use arch-specific RNG to initialize the entropy store Ben Hutchings
2012-08-07 3:28 ` [ 13/70] random: Adjust the number of loops when initializing Ben Hutchings
2012-08-07 3:28 ` Ben Hutchings [this message]
2012-08-07 3:28 ` [ 15/70] random: use lockless techniques in the interrupt path Ben Hutchings
2012-08-07 3:28 ` [ 16/70] random: create add_device_randomness() interface Ben Hutchings
2012-08-07 3:28 ` [ 17/70] usb: feed USB device information to the /dev/random driver Ben Hutchings
2012-08-07 3:28 ` [ 18/70] net: feed /dev/random with the MAC address when registering a device Ben Hutchings
2012-08-07 3:28 ` [ 19/70] random: use the arch-specific rng in xfer_secondary_pool Ben Hutchings
2012-08-07 3:28 ` [ 20/70] random: add new get_random_bytes_arch() function Ben Hutchings
2012-08-07 3:28 ` [ 21/70] rtc: wm831x: Feed the write counter into device_add_randomness() Ben Hutchings
2012-08-07 3:28 ` [ 22/70] mfd: wm831x: Feed the device UUID " Ben Hutchings
2012-08-07 3:28 ` [ 23/70] ASoC: wm8994: Ensure there are enough BCLKs for four channels Ben Hutchings
2012-08-07 3:28 ` [ 24/70] futex: Test for pi_mutex on fault in futex_wait_requeue_pi() Ben Hutchings
2012-08-07 3:28 ` [ 25/70] futex: Fix bug in WARN_ON for NULL q.pi_state Ben Hutchings
2012-08-07 3:28 ` [ 26/70] futex: Forbid uaddr == uaddr2 in futex_wait_requeue_pi() Ben Hutchings
2012-08-07 3:28 ` [ 27/70] video/smscufx: fix line counting in fb_write Ben Hutchings
2012-08-07 3:28 ` [ 28/70] Input: synaptics - handle out of bounds values from the hardware Ben Hutchings
2012-08-07 3:28 ` [ 29/70] ALSA: hda - Fix invalid D3 of headphone DAC on VT202x codecs Ben Hutchings
2012-08-07 3:28 ` [ 30/70] ALSA: mpu401: Fix missing initialization of irq field Ben Hutchings
2012-08-07 3:28 ` [ 31/70] x86, nops: Missing break resulting in incorrect selection on Intel Ben Hutchings
2012-08-07 3:28 ` [ 32/70] s390/mm: downgrade page table after fork of a 31 bit process Ben Hutchings
2012-08-07 3:28 ` [ 33/70] [IA64] Redefine ATOMIC_INIT and ATOMIC64_INIT to drop the casts Ben Hutchings
2012-08-07 3:28 ` [ 34/70] dm thin: reduce endio_hook pool size Ben Hutchings
2012-08-07 3:28 ` [ 35/70] dm thin: fix memory leak in process_prepared_mapping error paths Ben Hutchings
2012-08-07 3:28 ` [ 36/70] random: mix in architectural randomness in extract_buf() Ben Hutchings
2012-08-07 3:28 ` [ 37/70] asus-wmi: use ASUS_WMI_METHODID_DSTS2 as default DSTS ID Ben Hutchings
2012-08-07 3:28 ` [ 38/70] virtio-blk: Use block layer provided spinlock Ben Hutchings
2012-08-07 3:28 ` [ 39/70] s390/mm: fix fault handling for page table walk case Ben Hutchings
2012-08-07 3:28 ` [ 40/70] nfs: skip commit in releasepage if were freeing memory for fs-related reasons Ben Hutchings
2012-08-07 3:28 ` [ 41/70] md/raid1: dont abort a resync on the first badblock Ben Hutchings
2012-08-07 3:28 ` [ 42/70] pcdp: use early_ioremap/early_iounmap to access pcdp table Ben Hutchings
2012-08-07 3:28 ` [ 43/70] lib/vsprintf.c: kptr_restrict: fix pK-error in SysRq show-all-timers(Q) Ben Hutchings
2012-08-07 3:28 ` [ 44/70] nilfs2: fix deadlock issue between chcp and thaw ioctls Ben Hutchings
2012-08-07 3:28 ` [ 45/70] SUNRPC: return negative value in case rpcbind client creation error Ben Hutchings
2012-08-07 3:28 ` [ 46/70] ARM: 7466/1: disable interrupt before spinning endlessly Ben Hutchings
2012-08-07 3:28 ` [ 47/70] ARM: 7467/1: mutex: use generic xchg-based implementation for ARMv6+ Ben Hutchings
2012-08-07 3:28 ` [ 48/70] ARM: 7476/1: vfp: only clear vfp state for current cpu in vfp_pm_suspend Ben Hutchings
2012-08-07 3:28 ` [ 49/70] ARM: 7477/1: vfp: Always save VFP state in vfp_pm_suspend on UP Ben Hutchings
2012-08-07 3:28 ` [ 50/70] ARM: 7478/1: errata: extend workaround for erratum #720789 Ben Hutchings
2012-08-07 3:28 ` [ 51/70] ARM: Fix undefined instruction exception handling Ben Hutchings
2012-08-07 3:28 ` [ 52/70] USB: echi-dbgp: increase the controller wait time to come out of halt Ben Hutchings
2012-08-07 3:28 ` [ 53/70] ASoC: wm8962: Allow VMID time to fully ramp Ben Hutchings
2012-08-07 3:28 ` [ 54/70] mm/page_alloc.c: remove pageblock_default_order() Ben Hutchings
2012-08-07 3:28 ` [ 55/70] mm: setup pageblock_order before its used by sparsemem Ben Hutchings
2012-08-07 3:28 ` [ 56/70] mm: mmu_notifier: fix freed page still mapped in secondary MMU Ben Hutchings
2012-08-07 3:28 ` [ 57/70] mm: hugetlbfs: close race during teardown of hugetlbfs shared page tables Ben Hutchings
2012-08-07 3:28 ` [ 58/70] ALSA: snd-usb: fix clock source validity index Ben Hutchings
2012-08-07 3:28 ` [ 59/70] ALSA: hda - Support dock on Lenovo Thinkpad T530 with ALC269VC Ben Hutchings
2012-08-07 3:28 ` [ 60/70] ore: Fix out-of-bounds access in _ios_obj() Ben Hutchings
2012-08-07 3:28 ` [ 61/70] m68k: Make sys_atomic_cmpxchg_32 work on classic m68k Ben Hutchings
2012-08-07 3:28 ` [ 62/70] drm/i915: prefer wide & slow to fast & narrow in DP configs Ben Hutchings
2012-08-07 3:28 ` [ 63/70] rt2x00: Add support for BUFFALO WLI-UC-GNM2 to rt2800usb Ben Hutchings
2012-08-07 3:28 ` [ 64/70] drop_monitor: fix sleeping in invalid context warning Ben Hutchings
2012-08-07 3:29 ` [ 65/70] drop_monitor: Make updating data->skb smp safe Ben Hutchings
2012-08-07 3:29 ` [ 66/70] drop_monitor: prevent init path from scheduling on the wrong cpu Ben Hutchings
2012-08-07 3:29 ` [ 67/70] drop_monitor: dont sleep in atomic context Ben Hutchings
2012-08-07 3:29 ` [ 68/70] pch_uart: Fix missing break for 16 byte fifo Ben Hutchings
2012-08-07 3:29 ` [ 69/70] pch_uart: Fix rx error interrupt setting issue Ben Hutchings
2012-08-07 3:29 ` [ 70/70] pch_uart: Fix parity " Ben Hutchings
2012-08-07 3:49 ` [ 00/70] 3.2.27-stable review Ben Hutchings
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20120807032758.126541115@decadent.org.uk \
--to=ben@decadent.org.uk \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=ewust@umich.edu \
--cc=jhalderm@umich.edu \
--cc=linux-kernel@vger.kernel.org \
--cc=nadiah@cs.ucsd.edu \
--cc=stable@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=tytso@mit.edu \
--cc=zakir@umich.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®