From: Dave Hansen <dave.hansen@intel.com>
To: "Jason A. Donenfeld" <Jason@zx2c4.com>
Cc: x86@kernel.org, linux-coco@lists.linux.dev,
linux-kernel@vger.kernel.org, "Borislav Petkov" <bp@alien8.de>,
"Daniel P . Berrangé" <berrange@redhat.com>,
"Dave Hansen" <dave.hansen@linux.intel.com>,
"Elena Reshetova" <elena.reshetova@intel.com>,
"H . Peter Anvin" <hpa@zytor.com>,
"Ingo Molnar" <mingo@redhat.com>,
"Kirill A . Shutemov" <kirill.shutemov@linux.intel.com>,
"Theodore Ts'o" <tytso@mit.edu>,
"Thomas Gleixner" <tglx@linutronix.de>
Subject: Re: [PATCH v3] x86/coco: Require seeding RNG with RDRAND on CoCo systems
Date: Wed, 21 Feb 2024 15:35:28 -0800 [thread overview]
Message-ID: <5648f43d-76e4-4396-b626-411d60657c93@intel.com> (raw)
In-Reply-To: <CAHmME9rCQgY_DMmpOEJWO8qytNw3ErJNy9L-E7WzEKYHVyqCHA@mail.gmail.com>
On 2/21/24 15:09, Jason A. Donenfeld wrote:
> On Wed, Feb 21, 2024 at 11:47 PM Dave Hansen <dave.hansen@intel.com> wrote:
>> OK, so we're trying to get 256 bits of seed data from RDRAND?
>
> Yes. This fills a 32-byte buffer of longs up with output from
> arch_get_random_longs().
That's what it's doing mechanically, but what's the end goal?
>> But no pattern I could discern. Did you mean something different by
>> "platform drivers"?
>
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/arch/um/kernel/um_arch.c#n413
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/drivers/char/random.c#n655
Gotcha.
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/scripts/gcc-plugins/latent_entropy_plugin.c#n90
Isn't that one 32 HOST_WIDE_INTs and not 32 bytes? :)
>> If we're going to have arch/x86-specific crud, it would be great to make
>> it obvious and straightforward to those of us simple folk that are
>> familiar with arch/x86 code.
>
> If you insist, I'll stick a local `enum { RANDOM_BYTES_COUNT = 32 }`
> in that function or something. Seems unnecessary to me but if that's
> what you need no problem. Would that suffice? Or a different variable
> name? Or a comment on "what is 32 about?"
"what is 32 about?" would be great. What's the goal, and why is 32
enough to reach that goal?
next prev parent reply other threads:[~2024-02-21 23:35 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-02-21 12:32 Jason A. Donenfeld
2024-02-21 14:34 ` Reshetova, Elena
2024-02-21 15:36 ` Jason A. Donenfeld
2024-02-21 15:37 ` Kirill A . Shutemov
2024-02-21 15:51 ` Theodore Ts'o
2024-02-21 16:55 ` Dave Hansen
2024-02-21 17:19 ` Jason A. Donenfeld
2024-02-21 22:47 ` Dave Hansen
2024-02-21 23:09 ` Jason A. Donenfeld
2024-02-21 23:35 ` Dave Hansen [this message]
2024-02-22 2:05 ` [PATCH v4] " Jason A. Donenfeld
2024-02-23 22:05 ` Tom Lendacky
2024-02-24 1:14 ` Jason A. Donenfeld
2024-02-24 1:18 ` [PATCH v5] " Jason A. Donenfeld
2024-03-13 23:34 ` Jason A. Donenfeld
2024-03-14 11:14 ` Borislav Petkov
2024-03-26 11:21 ` Borislav Petkov
2024-03-26 16:07 ` [PATCH v6] " Jason A. Donenfeld
2024-03-28 15:13 ` Tom Lendacky
2024-04-04 9:11 ` [tip: x86/urgent] " tip-bot2 for Jason A. Donenfeld
2024-02-22 7:35 ` [PATCH v3] " Reshetova, Elena
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5648f43d-76e4-4396-b626-411d60657c93@intel.com \
--to=dave.hansen@intel.com \
--cc=Jason@zx2c4.com \
--cc=berrange@redhat.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=elena.reshetova@intel.com \
--cc=hpa@zytor.com \
--cc=kirill.shutemov@linux.intel.com \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=tglx@linutronix.de \
--cc=tytso@mit.edu \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome