From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:44858) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TSky9-0002Nf-Re for qemu-devel@nongnu.org; Mon, 29 Oct 2012 04:45:17 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TSky8-0003FR-OX for qemu-devel@nongnu.org; Mon, 29 Oct 2012 04:45:13 -0400 Received: from mail-we0-f173.google.com ([74.125.82.173]:36354) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TSky8-0003FL-Hu for qemu-devel@nongnu.org; Mon, 29 Oct 2012 04:45:12 -0400 Received: by mail-we0-f173.google.com with SMTP id t11so2321110wey.4 for ; Mon, 29 Oct 2012 01:45:11 -0700 (PDT) Sender: Paolo Bonzini Message-ID: <508E4215.6050803@redhat.com> Date: Mon, 29 Oct 2012 09:45:09 +0100 From: Paolo Bonzini MIME-Version: 1.0 References: <604401631.2277495.1351264128301.JavaMail.root@redhat.com> <871ugl44v5.fsf@codemonkey.ws> <508AB5C0.2000304@zytor.com> <508ADD66.5040909@redhat.com> <5ea4bbfb-b761-42ef-93f8-7c91fee0bb30@email.android.com> <508AE9A6.4060304@redhat.com> <508AF2C0.30404@zytor.com> In-Reply-To: <508AF2C0.30404@zytor.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Subject: Re: [Qemu-devel] [PATCH 0/6] add paravirtualization hwrng support List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: "H. Peter Anvin" Cc: Amit Shah , Anthony Liguori , Andreas Faerber , qemu-devel@nongnu.org Il 26/10/2012 22:29, H. Peter Anvin ha scritto: >>> This is surreal. Output from /dev/hwrng turns into output for /dev/random... it us guaranteed worse; period, end of story. >> > >> > Isn't that exactly what happens in bare-metal? hwrng -> rngd -> random. Instead here >> > we'd have, host hwrng -> virtio-rng-pci -> guest hwrng -> guest rngd -> guest random. >> > >> > The only difference is that you paravirtualize access to the host hwrng to a) distribute >> > entropy to multiple guests; b) support migration across hosts with different CPUs and >> > hardware. > First, hwrng is only one of the sources used by rngd. It can also > (currently) use RDRAND or TPM; additional sources are likely to be added > in the future. > > Second, the harvesting of environmental noise -- timings -- is not as > good in a VM as on plain hardware, so for the no-hwrng case it is better > for this to be done in the host than in the VM. Neither of these make /dev/random with virtio-rng-pci worse than without (as would be the case if you fed /dev/urandom). And migration works. This, and avoiding denial of service for the host's /dev/random, is all I care about at this time. There is always time to change defaults to something better. Paolo