| Summary: | rng-tools: rngd hang when use jitter entropy with internal timer | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Mingli Yu <mingli.yu> |
| Component: | oe-core other | Assignee: | Mingli Yu <mingli.yu> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Medium+ | CC: | JPEWhacker, randy.macleod |
| Version: | 3.3 | ||
| Target Milestone: | 3.4 M4 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | backport | ||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
We are following the general kernel security/ rngd recommendations. There are other sources of entropy such as virt-io. maybe we should be using haveved? (In reply to comment #1) > We are following the general kernel security/ rngd recommendations. > There are other sources of entropy such as virt-io. > > maybe we should be using haveved? The bug against the jitter entropy source, such as on the borad nxp-s32g2xx, we only have the jitter entropy source and also need to use the internal timer as the coarse resolution timer. The bug against the jitter entropy source, such as on the borad nxp-s32g2xx, we only have the jitter entropy source and also need to use the internal timer as the coarse resolution timer. Mingli, Please work with the upstream developers to figure out how to deal with the behaviour on this board. Again: We are following the general kernel security/ rngd recommendations. There are other sources of entropy such as virt-io. maybe we should be using haveved? We're talking about this on the oe-core email list. |
The rngd hang when the board only has jitter entropy and also coarse resolution timer. And the issue can be reproduced in any board when force to use the internal timer as below: 1, apply below patch for libjitterentropy recipe which rng-tools depends(this pach force to use the internal timer). $ git diff diff --git a/jitterentropy-base.c b/jitterentropy-base.c index 6dbb484..07397cb 100644 --- a/jitterentropy-base.c +++ b/jitterentropy-base.c @@ -1387,7 +1387,8 @@ int jent_entropy_init(void) if (sha3_tester()) return EHASH; - ret = jent_time_entropy_init(0); + //ret = jent_time_entropy_init(0); + ret = 1; #ifdef JENT_CONF_ENABLE_INTERNAL_TIMER jent_force_internal_timer = 0; 2, use the jitter entropy as below: rngd -f -x hwrng -x rdrand