Thread (10 messages) 10 messages, 3 authors, 2020-01-08

Re: [PATCH v8 2/3] arm64: random: Add data to pool from setup_arch()

From: Mark Rutland <mark.rutland@arm.com>
Date: 2020-01-08 17:20:50

On Tue, Jan 07, 2020 at 06:35:39PM +0000, Mark Brown wrote:
Since the arm64 ARCH_RANDOM implementation is not available until
cpufeature has determined the system capabilities it can't be used by
the generic random code to initialize the entropy pool for early use.
Instead explicitly add some data to the pool from setup_arch() if the
boot CPU supports v8.5-RNG, this is the point recommended by the generic
code.
This structure looks good to me.
quoted hunk ↗ jump to hunk
Signed-off-by: Mark Brown <broonie@kernel.org>
---
 arch/arm64/include/asm/archrandom.h | 24 ++++++++++++++++++++++++
 arch/arm64/kernel/setup.c           |  2 ++
 2 files changed, 26 insertions(+)
diff --git a/arch/arm64/include/asm/archrandom.h b/arch/arm64/include/asm/archrandom.h
index 364177954bef..1d9b94fa9c45 100644
--- a/arch/arm64/include/asm/archrandom.h
+++ b/arch/arm64/include/asm/archrandom.h
@@ -59,9 +59,33 @@ static inline bool __must_check arch_get_random_seed_int(unsigned int *v)
 	return ok;
 }
 
+/*
+ * Our ARCH_RANDOM implementation does not function until relatively
+ * late in the boot when cpufeature has detertmined system
+ * capabilities so the core code can't use arch_get_random*() to
+ * initialize, instead we call this function to inject data from
+ * setup_arch() if the boot CPU supports v8.5-RNG.
+ */
+static inline void arm64_add_early_rndr_entropy(void)
Can we mark this as __init so that people aren't tempted to use it at
runtime? I realsie it's inline, but it's at least something sparse can
check.
+{
+	unsigned long val;
+	int i;
+
+	/* Open code as we run prior to the first call to cpufeature. */
+	val = read_sysreg_s(SYS_ID_AA64ISAR0_EL1);
+	if (!((val >> ID_AA64ISAR0_RNDR_SHIFT) & 0xf))
+		return;
+
+	/* Add multiple values to mirror the generic code. */
+	for (i = 0; i < 16; i++)
+		if (__arm64_rndr(&val))
+			add_device_randomness(&val, sizeof(val));
+}
Given the next patch also needs to check the I reckon it is worth
factoring the ID register check into a helper:

/* Used on the boot CPU before the CPU feature framework is up */
static inline bool __init __early_cpu_has_rndr(void)
{
	unsigned long ftr = read_sysreg_s(SYS_ID_AA64ISAR0_EL1);
	return (ftr >> ID_AA64ISAR0_RNDR_SHIFT) & 0xf;
}
+
 #else
 
 static inline bool __arm64_rndr(unsigned long *v) { return false; }
+static inline void arm64_add_early_rndr_entropy(void) { }
... with a stub here:

static inline bool __init __early_cpu_has_rndr(void) { return false; }

... so the KASLR code can just check __early_cpu_has_rndr().

Thanks,
Mark.
quoted hunk ↗ jump to hunk
 
 #endif /* CONFIG_ARCH_RANDOM */
 #endif /* _ASM_ARCHRANDOM_H */
diff --git a/arch/arm64/kernel/setup.c b/arch/arm64/kernel/setup.c
index 56f664561754..170842965a32 100644
--- a/arch/arm64/kernel/setup.c
+++ b/arch/arm64/kernel/setup.c
@@ -344,6 +344,8 @@ void __init setup_arch(char **cmdline_p)
 	/* Init percpu seeds for random tags after cpus are set up. */
 	kasan_init_tags();
 
+	arm64_add_early_rndr_entropy();
+
 #ifdef CONFIG_ARM64_SW_TTBR0_PAN
 	/*
 	 * Make sure init_thread_info.ttbr0 always generates translation
-- 
2.20.1
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help