From mboxrd@z Thu Jan 1 00:00:00 1970 X-Msuck: nntp://news.gmane.org/gmane.linux.lib.musl.general/12304 Path: news.gmane.org!.POSTED!not-for-mail From: Rich Felker Newsgroups: gmane.linux.lib.musl.general Subject: Re: [PATCH] Add getrandom syscall wrapper function Date: Tue, 2 Jan 2018 13:09:37 -0500 Message-ID: <20180102180937.GL1627@brightrain.aerifal.cx> References: <20180101203123.12816-1-hauke@hauke-m.de> <20180101204748.GH1627@brightrain.aerifal.cx> <501306ff-c0e3-f1be-a81b-ba6e619fd807@hauke-m.de> <20180101220354.GI1627@brightrain.aerifal.cx> <20180102021403.GK1627@brightrain.aerifal.cx> <20180102152758.GB4871@port70.net> Reply-To: musl@lists.openwall.com NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Trace: blaine.gmane.org 1514916479 25982 195.159.176.226 (2 Jan 2018 18:07:59 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Tue, 2 Jan 2018 18:07:59 +0000 (UTC) User-Agent: Mutt/1.5.21 (2010-09-15) To: musl@lists.openwall.com Original-X-From: musl-return-12320-gllmg-musl=m.gmane.org@lists.openwall.com Tue Jan 02 19:07:55 2018 Return-path: Envelope-to: gllmg-musl@m.gmane.org Original-Received: from mother.openwall.net ([195.42.179.200]) by blaine.gmane.org with smtp (Exim 4.84_2) (envelope-from ) id 1eWQyb-0006Dr-MA for gllmg-musl@m.gmane.org; Tue, 02 Jan 2018 19:07:49 +0100 Original-Received: (qmail 28149 invoked by uid 550); 2 Jan 2018 18:09:50 -0000 Mailing-List: contact musl-help@lists.openwall.com; run by ezmlm Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-ID: Original-Received: (qmail 28131 invoked from network); 2 Jan 2018 18:09:49 -0000 Content-Disposition: inline In-Reply-To: <20180102152758.GB4871@port70.net> Original-Sender: Rich Felker Xref: news.gmane.org gmane.linux.lib.musl.general:12304 Archived-At: On Tue, Jan 02, 2018 at 04:27:59PM +0100, Szabolcs Nagy wrote: > * Rich Felker [2018-01-01 21:14:03 -0500]: > > > > glibc does not have a fallback for this syscall there was a long > > > > discussion about this, see here: https://lwn.net/Articles/711013/ > > > > As they never found a good solution for their fallback. I think musl > > > > should also not provide a fallback. > > > > Interesting that the biggest issue seems to have been about using file > > descriptors as the fallback. That's something I never considered using > > in musl since we have AT_RANDOM and sysctl on ancient kernels that > > lack it. There are a small number of kernels between when sysctl > > started spamming syslog with deprecation warnings and when AT_RANDOM > > was added but I don't really care about those; it still works anyway. > > note that getrandom gives new entropy after fork > but AT_RANDOM is the same. The concept of "new entropy" is not meaningful. Yes, a naive AT_RANDOM-based approach would share state between parent and child in a program that forks without exec, which would be bad, but the obvious way you do this is (1) consume AT_RANDOM and overwrite it with the output of the internal csPRNG so that getauxval(AT_RANDOM) doesn't leak sensitive state, and (2) step the csPRNG twice at fork, using the outputs as the new state in the parent and child so that neither can predict the other's state. Admittedly such a random number source is not hard against heartbleed-type attacks, so you probably should still prefer SYS_getrandom when it's available. On modern systems where people really care, it will be available anyway. Rich