Bug 14369

Summary: rng-tools: rngd hang when use jitter entropy with internal timer
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Mingli Yu <mingli.yu>
Component: oe-core otherAssignee: Mingli Yu <mingli.yu>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+ CC: JPEWhacker, randy.macleod
Version: 3.3   
Target Milestone: 3.4 M4   
Hardware: x86   
OS: Multiple   
Whiteboard: backport
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Mingli Yu 2021-04-29 07:07:23 UTC
The rngd hang when the board only has jitter entropy and also coarse resolution timer.

And the issue can be reproduced in any board when force to use the internal timer as below:
1, apply below patch for libjitterentropy recipe which rng-tools depends(this pach force to use the internal timer).
$ git diff
diff --git a/jitterentropy-base.c b/jitterentropy-base.c
index 6dbb484..07397cb 100644
--- a/jitterentropy-base.c
+++ b/jitterentropy-base.c
@@ -1387,7 +1387,8 @@ int jent_entropy_init(void)
        if (sha3_tester())
                return EHASH;
 
-       ret = jent_time_entropy_init(0);
+       //ret = jent_time_entropy_init(0);
+       ret = 1;
 
 #ifdef JENT_CONF_ENABLE_INTERNAL_TIMER
        jent_force_internal_timer = 0;

2, use the jitter entropy as below:
rngd -f -x hwrng -x rdrand
Comment 1 Randy MacLeod 2021-04-29 15:18:48 UTC
We are following the general kernel security/ rngd recommendations.
There are other sources of entropy such as virt-io. 

maybe we should be using haveved?
Comment 2 Mingli Yu 2021-04-30 02:04:50 UTC
(In reply to comment #1)
> We are following the general kernel security/ rngd recommendations.
> There are other sources of entropy such as virt-io. 
> 
> maybe we should be using haveved?

The bug against the jitter entropy source, such as on the borad nxp-s32g2xx, we only have the jitter entropy source and also need to use the internal timer as the coarse resolution timer.
Comment 3 Mingli Yu 2021-04-30 02:05:32 UTC
The bug against the jitter entropy source, such as on the borad nxp-s32g2xx, we only have the jitter entropy source and also need to use the internal timer as the coarse resolution timer.
Comment 4 Randy MacLeod 2021-05-06 14:35:13 UTC
Mingli, Please work with the upstream developers to figure out how to deal with the behaviour on this board.
Comment 5 Randy MacLeod 2021-05-06 14:36:09 UTC
Again:
We are following the general kernel security/ rngd recommendations.
There are other sources of entropy such as virt-io. 
maybe we should be using haveved?
Comment 6 Randy MacLeod 2021-05-13 15:33:36 UTC
We're talking about this on the oe-core email list.