* [PATCH] virtio: rng: add derating factor for use by hwrng core
@ 2014-08-13 19:09 Rusty Russell
2014-08-13 20:49 ` H. Peter Anvin
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Rusty Russell @ 2014-08-13 19:09 UTC (permalink / raw)
To: Linus Torvalds
Cc: linux-kernel, hpa, Amos Kong, ricardo.neri-calderon, tytso,
Amit Shah
The khwrngd thread is started when a hwrng device of sufficient
quality is registered. The virtio-rng device is backed by the
hypervisor, and we trust the hypervisor to provide real entropy.
A malicious hypervisor is a scenario that's irrelevant -- such a setup
is bound to cause all sorts of badness, and a compromised hwrng is not
the biggest threat.
Given this, we are certain the quality of randomness we receive is
perfectly trustworthy. Hence, we use 100% for the factor, indicating
maximum confidence in the source.
Signed-off-by: Amit Shah <amit.shah@redhat.com>
Signed-off-by: Rusty Russell <rusty@rustcorp.com.au>
---
Pretty small and contained patch; would be great if it is picked up for
3.17.
v2: re-word commit msg
[Agreed, re-sending to Linus with SOB before jumping on plane]
---
drivers/char/hw_random/virtio-rng.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/char/hw_random/virtio-rng.c
b/drivers/char/hw_random/virtio-rng.c
index 0027137..2e3139e 100644
--- a/drivers/char/hw_random/virtio-rng.c
+++ b/drivers/char/hw_random/virtio-rng.c
@@ -116,6 +116,7 @@ static int probe_common(struct virtio_device *vdev)
.cleanup = virtio_cleanup,
.priv = (unsigned long)vi,
.name = vi->name,
+ .quality = 1000,
};
vdev->priv = vi;
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH] virtio: rng: add derating factor for use by hwrng core
2014-08-13 19:09 [PATCH] virtio: rng: add derating factor for use by hwrng core Rusty Russell
@ 2014-08-13 20:49 ` H. Peter Anvin
2014-08-13 22:44 ` Theodore Ts'o
2014-08-14 18:51 ` Amos Kong
2 siblings, 0 replies; 4+ messages in thread
From: H. Peter Anvin @ 2014-08-13 20:49 UTC (permalink / raw)
To: Rusty Russell, Linus Torvalds
Cc: linux-kernel, Amos Kong, ricardo.neri-calderon, tytso, Amit Shah
On 08/13/2014 12:09 PM, Rusty Russell wrote:
> The khwrngd thread is started when a hwrng device of sufficient
> quality is registered. The virtio-rng device is backed by the
> hypervisor, and we trust the hypervisor to provide real entropy.
>
> A malicious hypervisor is a scenario that's irrelevant -- such a setup
> is bound to cause all sorts of badness, and a compromised hwrng is not
> the biggest threat.
>
> Given this, we are certain the quality of randomness we receive is
> perfectly trustworthy. Hence, we use 100% for the factor, indicating
> maximum confidence in the source.
>
> Signed-off-by: Amit Shah <amit.shah@redhat.com>
> Signed-off-by: Rusty Russell <rusty@rustcorp.com.au>
> ---
> Pretty small and contained patch; would be great if it is picked up for
> 3.17.
>
> v2: re-word commit msg
>
> [Agreed, re-sending to Linus with SOB before jumping on plane]
Reviewed-by: H. Peter Anvin <hpa@linux.intel.com>
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] virtio: rng: add derating factor for use by hwrng core
2014-08-13 19:09 [PATCH] virtio: rng: add derating factor for use by hwrng core Rusty Russell
2014-08-13 20:49 ` H. Peter Anvin
@ 2014-08-13 22:44 ` Theodore Ts'o
2014-08-14 18:51 ` Amos Kong
2 siblings, 0 replies; 4+ messages in thread
From: Theodore Ts'o @ 2014-08-13 22:44 UTC (permalink / raw)
To: Rusty Russell
Cc: Linus Torvalds, linux-kernel, hpa, Amos Kong,
ricardo.neri-calderon, Amit Shah
On Thu, Aug 14, 2014 at 04:39:07AM +0930, Rusty Russell wrote:
> The khwrngd thread is started when a hwrng device of sufficient
> quality is registered. The virtio-rng device is backed by the
> hypervisor, and we trust the hypervisor to provide real entropy.
>
> A malicious hypervisor is a scenario that's irrelevant -- such a setup
> is bound to cause all sorts of badness, and a compromised hwrng is not
> the biggest threat.
s/malicious/malicious or badly implemented/
s/is not the biggest threat/is the least of the user's worries/
> Given this, we are certain the quality of randomness we receive is
> perfectly trustworthy. Hence, we use 100% for the factor, indicating
> maximum confidence in the source.
s/we are certain/we might as well assume that/
I won't insist on the wording changes, but I think it's a better way
of phrasing things.
Cheers,
- Ted
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] virtio: rng: add derating factor for use by hwrng core
2014-08-13 19:09 [PATCH] virtio: rng: add derating factor for use by hwrng core Rusty Russell
2014-08-13 20:49 ` H. Peter Anvin
2014-08-13 22:44 ` Theodore Ts'o
@ 2014-08-14 18:51 ` Amos Kong
2 siblings, 0 replies; 4+ messages in thread
From: Amos Kong @ 2014-08-14 18:51 UTC (permalink / raw)
To: Rusty Russell
Cc: Linus Torvalds, linux-kernel, hpa, ricardo.neri-calderon, tytso,
Amit Shah
On Thu, Aug 14, 2014 at 04:39:07AM +0930, Rusty Russell wrote:
> The khwrngd thread is started when a hwrng device of sufficient
> quality is registered. The virtio-rng device is backed by the
> hypervisor, and we trust the hypervisor to provide real entropy.
>
> A malicious hypervisor is a scenario that's irrelevant -- such a setup
> is bound to cause all sorts of badness, and a compromised hwrng is not
> the biggest threat.
>
> Given this, we are certain the quality of randomness we receive is
> perfectly trustworthy. Hence, we use 100% for the factor, indicating
> maximum confidence in the source.
>
> Signed-off-by: Amit Shah <amit.shah@redhat.com>
> Signed-off-by: Rusty Russell <rusty@rustcorp.com.au>
Reviewed-by: Amos Kong <akong@redhat.com>
> ---
> Pretty small and contained patch; would be great if it is picked up for
> 3.17.
>
> v2: re-word commit msg
>
> [Agreed, re-sending to Linus with SOB before jumping on plane]
> ---
> drivers/char/hw_random/virtio-rng.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/drivers/char/hw_random/virtio-rng.c
> b/drivers/char/hw_random/virtio-rng.c
> index 0027137..2e3139e 100644
> --- a/drivers/char/hw_random/virtio-rng.c
> +++ b/drivers/char/hw_random/virtio-rng.c
> @@ -116,6 +116,7 @@ static int probe_common(struct virtio_device *vdev)
> .cleanup = virtio_cleanup,
> .priv = (unsigned long)vi,
> .name = vi->name,
> + .quality = 1000,
> };
> vdev->priv = vi;
>
> --
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at http://www.tux.org/lkml/
--
Amos.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2014-08-14 18:51 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-08-13 19:09 [PATCH] virtio: rng: add derating factor for use by hwrng core Rusty Russell
2014-08-13 20:49 ` H. Peter Anvin
2014-08-13 22:44 ` Theodore Ts'o
2014-08-14 18:51 ` Amos Kong
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox