Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #204322 > unrolled thread
| Started by | basti <mailinglist@unix-solution.de> |
|---|---|
| First post | 2019-01-11 20:30 +0100 |
| Last post | 2019-01-12 09:20 +0100 |
| Articles | 4 — 4 participants |
Back to article view | Back to linux.debian.user
Monitor process who is eat my entropy basti <mailinglist@unix-solution.de> - 2019-01-11 20:30 +0100
Re: Monitor process who is eat my entropy Reco <recoverym4n@enotuniq.net> - 2019-01-11 20:40 +0100
Re: Monitor process who is eat my entropy Andy Smith <andy@strugglers.net> - 2019-01-11 21:50 +0100
Re: Monitor process who is eat my entropy Lucio <lucio@sulweb.org> - 2019-01-12 09:20 +0100
| From | basti <mailinglist@unix-solution.de> |
|---|---|
| Date | 2019-01-11 20:30 +0100 |
| Subject | Monitor process who is eat my entropy |
| Message-ID | <xfaFc-8pt-5@gated-at.bofh.it> |
Hello, is there a way to monitor processes that access /dev/urandom and show how may entropy the get? I have try lsof /dev/urandom without luck. Best regards,
[toc] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2019-01-11 20:40 +0100 |
| Message-ID | <xfaOS-8sE-13@gated-at.bofh.it> |
| In reply to | #204322 |
On Fri, Jan 11, 2019 at 08:28:18PM +0100, basti wrote: > Hello, > > is there a way to monitor processes that access /dev/urandom auditctl -w /dev/urandom -r remove it with auditctl -D > and show how may entropy the get? You'll probably need some advanced kernel-level tracing facility (such as BPF) for that. Reco
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2019-01-11 21:50 +0100 |
| Message-ID | <xfbUC-DV-3@gated-at.bofh.it> |
| In reply to | #204323 |
Hello,
On Fri, Jan 11, 2019 at 10:33:39PM +0300, Reco wrote:
> On Fri, Jan 11, 2019 at 08:28:18PM +0100, basti wrote:
> > is there a way to monitor processes that access /dev/urandom
>
> auditctl -w /dev/urandom -r
>
> remove it with
>
> auditctl -D
Note also that one should not really be concerned with reads from
urandom because this does not deplete the entropy pool, i.e. urandom
is inexhaustible.
/dev/random is the one which blocks, but I should think that reading
directly from either device is now deprecated in favour of system
calls, which are not going to open and read a device file. So
tracing that will not provide what is ultimately wanted, though it
does satisfy the letter of the request.
I think getrandom is supposed to be used these days:
https://manpages.debian.org/stretch/manpages-dev/getrandom.2.en.html
So indeed as you suggest, a different kind of tracing like BPF will
be more appropriate. That's beyond me at that point, though.
Cheers,
Andy
--
https://bitfolk.com/ -- No-nonsense VPS hosting
[toc] | [prev] | [next] | [standalone]
| From | Lucio <lucio@sulweb.org> |
|---|---|
| Date | 2019-01-12 09:20 +0100 |
| Message-ID | <xfmGl-7pV-1@gated-at.bofh.it> |
| In reply to | #204322 |
Hello, Il 11/01/19 20:28, basti ha scritto: > I have try lsof /dev/urandom without luck. I'm afraid /dev/urandom is not the only way to get random bytes from the kernel. Maybe the `top` command can help, it does not filter specifically by entropy usage, but processes that use a lot of entropy usually hit the CPU hard.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web