All of lore.kernel.org
 help / color / mirror / Atom feed
From: Alexander Clouter <alex@digriz.org.uk>
To: linux-kernel@vger.kernel.org
Subject: Re: random(4) driver questions
Date: Sat, 25 Jun 2011 13:53:59 +0100	[thread overview]
Message-ID: <7c2hd8-j3t.ln1@chipmunk.wormnet.eu> (raw)
In-Reply-To: BANLkTinC7vfaRWf5TK9gJuQVtVwDkEQFcQ@mail.gmail.com

Sandy Harris <sandyinchina@gmail.com> wrote:
> 
> One problem they pointed out is that there may be little entropy 
> available on a Linux-based router; no keyboard or mouse, solid state 
> storage so no disk entropy, and an enemy might observe network 
> activity, so network interrupts give little or no useful entropy.
> 
I vaguely recall network interrupts (anything that can be externally 
influenced) can be snooped upon so their use is discouraged.  Turns out 
IRQF_SAMPLE_RANDOM is scheduled for destruction, 
Documentation/feature-removal-schedule.txt.

> The only in-kernel solution I can think of would be to add something 
> in the system call interface to make very system call throw timing 
> information into the pool. I very much doubt, though, that that is a 
> good idea. What do others think, and does anyone have a better idea?
> 
An option I used, no idea if it safe though, for my headless colo box 
that seemed to always be running out of entropy was use a sleep() timing 
daemon:

http://www.vanheusden.com/te/

There was no chance of me using the ALSA/video4linux approach also on 
that site as I had a SPARC server so it was my only real choice.  Seems 
to work well, but had to apply a patch to stop it insanely spinning the 
CPU un-necessarily (the author unfortunately never responded):

http://stuff.digriz.org.uk/timer-select.diff

Another tool I found in my travels was HAVEGE:

http://www.irisa.fr/caps/projects/hipsor/index.php

Again, no idea if this is a good idea.

Of course in the VM world, the timer approach probably would work.

Cheers

-- 
Alexander Clouter
.sigmonster says: Some people only open up to tell you that they're closed.


  reply	other threads:[~2011-06-25 13:10 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-06-25  5:51 random(4) driver questions Sandy Harris
2011-06-25 12:53 ` Alexander Clouter [this message]
2011-06-27 14:54 ` Ted Ts'o
2011-06-27 15:08   ` Sasha Levin
2011-06-28  4:44   ` Johann Meier
2011-06-28  5:47     ` Sandy Harris
2011-06-28 19:44       ` Henrique de Moraes Holschuh
2011-06-28  6:02   ` Sandy Harris
2011-06-28 14:42     ` Ted Ts'o

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7c2hd8-j3t.ln1@chipmunk.wormnet.eu \
    --to=alex@digriz.org.uk \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.