mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com>
To: "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"stable@vger.kernel.org" <stable@vger.kernel.org>
Cc: Harald Freudenberger <freude@linux.vnet.ibm.com>,
	Martin Schwidefsky <schwidefsky@de.ibm.com>,
	"Levin, Alexander (Sasha Levin)" <alexander.levin@verizon.com>
Subject: [PATCH review for 4.9 45/50] s390/prng: Adjust generation of entropy to produce real 256 bits.
Date: Sat, 7 Oct 2017 22:36:57 +0000	[thread overview]
Message-ID: <20171007223636.24797-45-alexander.levin@verizon.com> (raw)
In-Reply-To: <20171007223636.24797-1-alexander.levin@verizon.com>

From: Harald Freudenberger <freude@linux.vnet.ibm.com>

[ Upstream commit d34b1acb78af41b8b8d5c60972b6555ea19f7564 ]

The generate_entropy function used a sha256 for compacting
together 256 bits of entropy into 32 bytes hash. However, it
is questionable if a sha256 can really be used here, as
potential collisions may reduce the max entropy fitting into
a 32 byte hash value. So this batch introduces the use of
sha512 instead and the required buffer adjustments for the
calling functions.

Further more the working buffer for the generate_entropy
function has been widened from one page to two pages. So now
1024 stckf invocations are used to gather 256 bits of
entropy. This has been done to be on the save side if the
jitters of stckf values isn't as good as supposed.

Signed-off-by: Harald Freudenberger <freude@linux.vnet.ibm.com>
Signed-off-by: Martin Schwidefsky <schwidefsky@de.ibm.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
 arch/s390/crypto/prng.c | 40 ++++++++++++++++++++++++----------------
 1 file changed, 24 insertions(+), 16 deletions(-)

diff --git a/arch/s390/crypto/prng.c b/arch/s390/crypto/prng.c
index 1113389d0a39..fe7368a41aa8 100644
--- a/arch/s390/crypto/prng.c
+++ b/arch/s390/crypto/prng.c
@@ -110,22 +110,30 @@ static const u8 initial_parm_block[32] __initconst = {
 
 /*** helper functions ***/
 
+/*
+ * generate_entropy:
+ * This algorithm produces 64 bytes of entropy data based on 1024
+ * individual stckf() invocations assuming that each stckf() value
+ * contributes 0.25 bits of entropy. So the caller gets 256 bit
+ * entropy per 64 byte or 4 bits entropy per byte.
+ */
 static int generate_entropy(u8 *ebuf, size_t nbytes)
 {
 	int n, ret = 0;
-	u8 *pg, *h, hash[32];
+	u8 *pg, *h, hash[64];
 
-	pg = (u8 *) __get_free_page(GFP_KERNEL);
+	/* allocate 2 pages */
+	pg = (u8 *) __get_free_pages(GFP_KERNEL, 1);
 	if (!pg) {
 		prng_errorflag = PRNG_GEN_ENTROPY_FAILED;
 		return -ENOMEM;
 	}
 
 	while (nbytes) {
-		/* fill page with urandom bytes */
-		get_random_bytes(pg, PAGE_SIZE);
-		/* exor page with stckf values */
-		for (n = 0; n < PAGE_SIZE / sizeof(u64); n++) {
+		/* fill pages with urandom bytes */
+		get_random_bytes(pg, 2*PAGE_SIZE);
+		/* exor pages with 1024 stckf values */
+		for (n = 0; n < 2 * PAGE_SIZE / sizeof(u64); n++) {
 			u64 *p = ((u64 *)pg) + n;
 			*p ^= get_tod_clock_fast();
 		}
@@ -134,8 +142,8 @@ static int generate_entropy(u8 *ebuf, size_t nbytes)
 			h = hash;
 		else
 			h = ebuf;
-		/* generate sha256 from this page */
-		cpacf_kimd(CPACF_KIMD_SHA_256, h, pg, PAGE_SIZE);
+		/* hash over the filled pages */
+		cpacf_kimd(CPACF_KIMD_SHA_512, h, pg, 2*PAGE_SIZE);
 		if (n < sizeof(hash))
 			memcpy(ebuf, hash, n);
 		ret += n;
@@ -143,7 +151,7 @@ static int generate_entropy(u8 *ebuf, size_t nbytes)
 		nbytes -= n;
 	}
 
-	free_page((unsigned long)pg);
+	free_pages((unsigned long)pg, 1);
 	return ret;
 }
 
@@ -334,7 +342,7 @@ static int __init prng_sha512_selftest(void)
 static int __init prng_sha512_instantiate(void)
 {
 	int ret, datalen;
-	u8 seed[64];
+	u8 seed[64 + 32 + 16];
 
 	pr_debug("prng runs in SHA-512 mode "
 		 "with chunksize=%d and reseed_limit=%u\n",
@@ -357,12 +365,12 @@ static int __init prng_sha512_instantiate(void)
 	if (ret)
 		goto outfree;
 
-	/* generate initial seed bytestring, first 48 bytes of entropy */
-	ret = generate_entropy(seed, 48);
-	if (ret != 48)
+	/* generate initial seed bytestring, with 256 + 128 bits entropy */
+	ret = generate_entropy(seed, 64 + 32);
+	if (ret != 64 + 32)
 		goto outfree;
 	/* followed by 16 bytes of unique nonce */
-	get_tod_clock_ext(seed + 48);
+	get_tod_clock_ext(seed + 64 + 32);
 
 	/* initial seed of the ppno drng */
 	cpacf_ppno(CPACF_PPNO_SHA512_DRNG_SEED,
@@ -395,9 +403,9 @@ static void prng_sha512_deinstantiate(void)
 static int prng_sha512_reseed(void)
 {
 	int ret;
-	u8 seed[32];
+	u8 seed[64];
 
-	/* generate 32 bytes of fresh entropy */
+	/* fetch 256 bits of fresh entropy */
 	ret = generate_entropy(seed, sizeof(seed));
 	if (ret != sizeof(seed))
 		return ret;
-- 
2.11.0

  parent reply	other threads:[~2017-10-07 22:57 UTC|newest]

Thread overview: 51+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-10-07 22:36 [PATCH review for 4.9 01/50] cpufreq: Do not clear real_cpus mask on policy init Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 02/50] crypto: ccp - Set the AES size field for all modes Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 03/50] staging: fsl-mc: Add missing header Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 06/50] scsi: megaraid_sas: Do not set fp_possible if TM capable for non-RW syspdIO, change fp_possible to bool Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 05/50] PM / wakeirq: report a wakeup_event on dedicated wekup irq Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 07/50] mmc: s3cmci: include linux/interrupt.h for tasklet_struct Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 04/50] IB/mlx5: Assign DSCP for R-RoCE QPs Address Path Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 11/50] staging: rtl8712u: Fix endian settings for structs describing network packets Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 08/50] mfd: ab8500-sysctrl: Handle probe deferral Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 10/50] bnxt_en: Added PCI IDs for BCM57452 and BCM57454 ASICs Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 09/50] mfd: axp20x: Fix axp288 PEK_DBR and PEK_DBF irqs being swapped Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 12/50] PCI/MSI: Return failure when msix_setup_entries() fails Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 15/50] ext4: do not use stripe_width if it is not set Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 13/50] net: mvneta: fix build errors when linux/phy*.h is removed from net/dsa.h Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 14/50] ext4: fix stripe-unaligned allocations Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 17/50] i2c: riic: correctly finish transfers Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 16/50] net/ena: change driver's default timeouts Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 18/50] drm/amdgpu: when dpm disabled, also need to stop/start vce Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 19/50] perf tools: Only increase index if perf_evsel__new_idx() succeeds Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 22/50] clocksource/drivers/arm_arch_timer: Add dt binding for hisilicon-161010101 erratum Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 21/50] drm/fsl-dcu: check for clk_prepare_enable() error Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 20/50] iwlwifi: mvm: use the PROBE_RESP_QUEUE to send deauth to unknown station Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 23/50] net: phy: dp83867: Recover from "port mirroring" N/A MODE4 Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 28/50] mtd: nand: sunxi: Fix the non-polling case in sunxi_nfc_wait_events() Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 24/50] [media] cx231xx: Fix I2C on Internal Master 3 Bus Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 25/50] ath10k: fix reading sram contents for QCA4019 Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 27/50] drm/msm/dsi: Set msm_dsi->encoders before initializing bridge Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 26/50] clk: sunxi-ng: Check kzalloc() for errors and cleanup error path Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 32/50] scsi: aacraid: Process Error for response I/O Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 31/50] xen/manage: correct return value check on xenbus_scanf() Levin, Alexander (Sasha Levin)
2017-10-10 12:49   ` Boris Ostrovsky
2017-10-24  1:39     ` Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 29/50] dmaengine: sun6i: allow build on ARM64 platforms (sun50i) Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 30/50] gpio: mcp23s08: Select REGMAP/REGMAP_I2C to fix build error Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 33/50] platform/x86: intel_mid_thermal: Fix module autoload Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 36/50] staging: lustre: ptlrpc: skip lock if export failed Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 34/50] staging: lustre: llite: don't invoke direct_IO for the EOF case Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 35/50] staging: lustre: hsm: stack overrun in hai_dump_data_field Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 38/50] brcmfmac: check brcmf_bus_get_memdump result for error Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 37/50] staging: lustre: lmv: Error not handled for lmv_find_target Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 40/50] vfs: open() with O_CREAT should not create inodes with unknown ids Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 39/50] ASoC: omap-mcbsp: Add PM QoS support for McBSP to prevent glitches Levin, Alexander (Sasha Levin)
2017-10-09  8:36   ` Mark Brown
2017-10-24  2:12     ` Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 41/50] ASoC: Intel: boards: remove .pm_ops in all Atom/DPCM machine drivers Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 44/50] s390/dasd: check for device error pointer within state change interrupts Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 43/50] mei: return error on notification request to a disconnected client Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 42/50] [media] exynos4-is: fimc-is: Unmap region obtained by of_iomap() Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` [PATCH review for 4.9 46/50] s390/crypto: Extend key length check for AES-XTS in fips mode Levin, Alexander (Sasha Levin)
2017-10-07 22:36 ` Levin, Alexander (Sasha Levin) [this message]
2017-10-07 22:36 ` [PATCH review for 4.9 47/50] [media] bt8xx: fix memory leak Levin, Alexander (Sasha Levin)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20171007223636.24797-45-alexander.levin@verizon.com \
    --to=alexander.levin@verizon.com \
    --cc=freude@linux.vnet.ibm.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=schwidefsky@de.ibm.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®