Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1577418

Re: [PATCH] Revert "hwrng: core - zeroize buffers with random data"

From Stephan Müller <smueller@chronox.de>
Newsgroups linux.kernel
Subject Re: [PATCH] Revert "hwrng: core - zeroize buffers with random data"
Date 2017-02-09 10:40 +0100
Message-ID <t8TmO-4qm-17@gated-at.bofh.it> (permalink)
References <t8MbE-81G-7@gated-at.bofh.it> <t8MbE-81G-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Am Mittwoch, 8. Februar 2017, 17:57:23 CET schrieb Linus Torvalds:

Hi Linus,

> Stephan, Herbert? The zeroes in /dev/hwrng output are obviously
> complete crap, so there's something badly wrong somewhere.
> 
> The locking, for example, is completely buggered. There's even a
> comment about it, but that comment makes the correct observation of
> "but y'know: randomness". But the memset() also being outside the lock
> makes a complete joke of the whole thing.

That is correct, the patch is broken and should be reverted.

May I ask, however, why the add_device_randomness is invoked outside the lock 
as well. Shouldn't it be moved into the lock?

Besides, I still would think that a memset(0) is needed because we have long-
living memory locations (rng_buffer and rng_fillbuf) which may be overwritten 
sporadically. As these memory locations are expected to hold entropy, they 
should be overwritten as soon as the data is processed. Obviously, such memset 
must be done within the lock.

Ciao
Stephan

Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Re: [PATCH] Revert "hwrng: core - zeroize buffers with random data" Linus Torvalds <torvalds@linux-foundation.org> - 2017-02-09 03:00 +0100
  Re: [PATCH] Revert "hwrng: core - zeroize buffers with random data" Stephan Müller <smueller@chronox.de> - 2017-02-09 10:40 +0100

csiph-web