From: Alexander Clouter <alex@digriz.org.uk>
To: linux-kernel@vger.kernel.org
Subject: Re: random(4) driver questions
Date: Sat, 25 Jun 2011 13:53:59 +0100 [thread overview]
Message-ID: <7c2hd8-j3t.ln1@chipmunk.wormnet.eu> (raw)
In-Reply-To: BANLkTinC7vfaRWf5TK9gJuQVtVwDkEQFcQ@mail.gmail.com
Sandy Harris <sandyinchina@gmail.com> wrote:
>
> One problem they pointed out is that there may be little entropy
> available on a Linux-based router; no keyboard or mouse, solid state
> storage so no disk entropy, and an enemy might observe network
> activity, so network interrupts give little or no useful entropy.
>
I vaguely recall network interrupts (anything that can be externally
influenced) can be snooped upon so their use is discouraged. Turns out
IRQF_SAMPLE_RANDOM is scheduled for destruction,
Documentation/feature-removal-schedule.txt.
> The only in-kernel solution I can think of would be to add something
> in the system call interface to make very system call throw timing
> information into the pool. I very much doubt, though, that that is a
> good idea. What do others think, and does anyone have a better idea?
>
An option I used, no idea if it safe though, for my headless colo box
that seemed to always be running out of entropy was use a sleep() timing
daemon:
http://www.vanheusden.com/te/
There was no chance of me using the ALSA/video4linux approach also on
that site as I had a SPARC server so it was my only real choice. Seems
to work well, but had to apply a patch to stop it insanely spinning the
CPU un-necessarily (the author unfortunately never responded):
http://stuff.digriz.org.uk/timer-select.diff
Another tool I found in my travels was HAVEGE:
http://www.irisa.fr/caps/projects/hipsor/index.php
Again, no idea if this is a good idea.
Of course in the VM world, the timer approach probably would work.
Cheers
--
Alexander Clouter
.sigmonster says: Some people only open up to tell you that they're closed.
next prev parent reply other threads:[~2011-06-25 13:10 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-06-25 5:51 random(4) driver questions Sandy Harris
2011-06-25 12:53 ` Alexander Clouter [this message]
2011-06-27 14:54 ` Ted Ts'o
2011-06-27 15:08 ` Sasha Levin
2011-06-28 4:44 ` Johann Meier
2011-06-28 5:47 ` Sandy Harris
2011-06-28 19:44 ` Henrique de Moraes Holschuh
2011-06-28 6:02 ` Sandy Harris
2011-06-28 14:42 ` Ted Ts'o
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=7c2hd8-j3t.ln1@chipmunk.wormnet.eu \
--to=alex@digriz.org.uk \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.