Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1506383

Re: why getrandom blocking does not work with /dev/urandom

From Theodore Ts'o <tytso@mit.edu>
Newsgroups linux.kernel
Subject Re: why getrandom blocking does not work with /dev/urandom
Date 2016-10-22 07:20 +0200
Message-ID <suWSR-7yB-5@gated-at.bofh.it> (permalink)
References <suVtL-6sM-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Sat, Oct 22, 2016 at 05:43:36AM +0200, Stephan Mueller wrote:
> Hi Ted,
> 
> as mentioned, I looked a bit deeper into the issue of adding the blocking 
> behavior of getrandom to /dev/urandom.
> 
> As you and I already identified, moving that blocking behavior to /dev/urandom 
> simply does not work. The system does not boot.
> 
> The reason to this issue is actually quite simple. The init process of systemd 
> reads /dev/urandom for whatever purpose. Now, when /dev/urandom blocks during 
> boot, systemd will be blocked too. That means that user space (either in the 
> initramfs or with the regular root partition) is set up.

I think you mean "is blocked from being set up".

> When there is no user space initialized, there are no devices set up. The 
> network card is not initialized, the block devices are not mounted, other 
> devices are not initialized. That means that neither interrupts nor block 
> device events are registered.

Well, those devices which are have already been initialized before
systemd starts will be fine.  Personally I believe in using built-in
drivers instead of depending on kernel modules for everything, but for
distribution kernels, yes, that's true.

In any case, yes, you're not telling me anything I didn't know.  What
I didn't know and still don't know is *why* systemd is tryinig to read
from /dev/urandom.  e.g., is it trying to initialize cryptographic
keys, the better to allow the Russians or the Chinese to set up
botnets which can take over IOT devices and paralyze root nameservers?
Or is it reading /dev/urandom for purely stupid, pointless,
non-cryptographic reasons?

I'm not sure which is worse, actually....

						- Ted

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

why getrandom blocking does not work with /dev/urandom Stephan Mueller <smueller@chronox.de> - 2016-10-22 05:50 +0200
  Re: why getrandom blocking does not work with /dev/urandom Theodore Ts'o <tytso@mit.edu> - 2016-10-22 07:20 +0200
    Re: why getrandom blocking does not work with /dev/urandom Stephan Mueller <smueller@chronox.de> - 2016-10-23 16:20 +0200

csiph-web