diff options
author | Conrad Meyer <cem@FreeBSD.org> | 2020-10-10 21:52:00 +0000 |
---|---|---|
committer | Conrad Meyer <cem@FreeBSD.org> | 2020-10-10 21:52:00 +0000 |
commit | f8e8a06d23a11bce26d67607d84dad2dd3e6c0f0 (patch) | |
tree | f64dd0b028128986eb53dcd7230c8d63015e38f9 /sys/riscv | |
parent | 10b1a17594a27f83c3ddbce44814f15a0b6bab91 (diff) | |
download | src-f8e8a06d23a11bce26d67607d84dad2dd3e6c0f0.tar.gz src-f8e8a06d23a11bce26d67607d84dad2dd3e6c0f0.zip |
random(4) FenestrasX: Push root seed version to arc4random(3)
Push the root seed version to userspace through the VDSO page, if
the RANDOM_FENESTRASX algorithm is enabled. Otherwise, there is no
functional change. The mechanism can be disabled with
debug.fxrng_vdso_enable=0.
arc4random(3) obtains a pointer to the root seed version published by
the kernel in the shared page at allocation time. Like arc4random(9),
it maintains its own per-process copy of the seed version corresponding
to the root seed version at the time it last rekeyed. On read requests,
the process seed version is compared with the version published in the
shared page; if they do not match, arc4random(3) reseeds from the
kernel before providing generated output.
This change does not implement the FenestrasX concept of PCPU userspace
generators seeded from a per-process base generator. That change is
left for future discussion/work.
Reviewed by: kib (previous version)
Approved by: csprng (me -- only touching FXRNG here)
Differential Revision: https://reviews.freebsd.org/D22839
Notes
Notes:
svn path=/head/; revision=366622
Diffstat (limited to 'sys/riscv')
-rw-r--r-- | sys/riscv/riscv/elf_machdep.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/sys/riscv/riscv/elf_machdep.c b/sys/riscv/riscv/elf_machdep.c index 813e8e6c869a..06d117128ef7 100644 --- a/sys/riscv/riscv/elf_machdep.c +++ b/sys/riscv/riscv/elf_machdep.c @@ -84,7 +84,8 @@ struct sysentvec elf64_freebsd_sysvec = { .sv_setregs = exec_setregs, .sv_fixlimit = NULL, .sv_maxssiz = NULL, - .sv_flags = SV_ABI_FREEBSD | SV_LP64 | SV_SHP | SV_ASLR, + .sv_flags = SV_ABI_FREEBSD | SV_LP64 | SV_SHP | SV_ASLR | + SV_RNG_SEED_VER, .sv_set_syscall_retval = cpu_set_syscall_retval, .sv_fetch_syscall_args = cpu_fetch_syscall_args, .sv_syscallnames = syscallnames, |