Commit 26192dfc authored by Lennart Poettering's avatar Lennart Poettering
Browse files

random-seed: honour kernel pool size when saving/restoring seed

parent 5481ab2b
...@@ -61,8 +61,18 @@ ...@@ -61,8 +61,18 @@
* decode exit codes in systemctl status * decode exit codes in systemctl status
* systemctl: ln -s output muss abschaltbar sein, und warning wenn [Install] leer ist.
* /etc/modules.d/*.modules in systemd-modules-load
* X-Interactive is kaputt
* universal fallback for hostname
External: External:
* procps, psmisc, sysvinit-tools, hostname → util-linux-ng
* nologin nach /var/run https://bugzilla.redhat.com/show_bug.cgi?id=624489 * nologin nach /var/run https://bugzilla.redhat.com/show_bug.cgi?id=624489
* make sysinit honour forcefsck/fastboot from the kernel command line fsck.mode=auto|force|skip * make sysinit honour forcefsck/fastboot from the kernel command line fsck.mode=auto|force|skip
......
...@@ -28,11 +28,15 @@ ...@@ -28,11 +28,15 @@
#include "log.h" #include "log.h"
#include "util.h" #include "util.h"
#define POOL_SIZE_MIN 512
int main(int argc, char *argv[]) { int main(int argc, char *argv[]) {
int seed_fd = -1, random_fd = -1; int seed_fd = -1, random_fd = -1;
int ret = 1; int ret = 1;
uint8_t buf[512]; void* buf;
size_t buf_size = 0;
ssize_t r; ssize_t r;
FILE *f;
if (argc != 2) { if (argc != 2) {
log_error("This program requires one argument."); log_error("This program requires one argument.");
...@@ -43,6 +47,20 @@ int main(int argc, char *argv[]) { ...@@ -43,6 +47,20 @@ int main(int argc, char *argv[]) {
log_parse_environment(); log_parse_environment();
log_open(); log_open();
/* Read pool size, if possible */
if ((f = fopen("/proc/sys/kernel/random/poolsize", "re"))) {
fscanf(f, "%zu", &buf_size);
fclose(f);
}
if (buf_size <= POOL_SIZE_MIN)
buf_size = POOL_SIZE_MIN;
if (!(buf = malloc(buf_size))) {
log_error("Failed to allocate buffer.");
goto finish;
}
/* When we load the seed we read it and write it to the device /* When we load the seed we read it and write it to the device
* and then immediately update the saved seed with new data, * and then immediately update the saved seed with new data,
* to make sure the next boot gets seeded differently. */ * to make sure the next boot gets seeded differently. */
...@@ -63,12 +81,12 @@ int main(int argc, char *argv[]) { ...@@ -63,12 +81,12 @@ int main(int argc, char *argv[]) {
} }
} }
if ((r = loop_read(seed_fd, buf, sizeof(buf), false)) != sizeof(buf)) if ((r = loop_read(seed_fd, buf, buf_size, false)) <= 0)
log_error("Failed to read seed file: %s", r < 0 ? strerror(errno) : "EOF"); log_error("Failed to read seed file: %s", r < 0 ? strerror(errno) : "EOF");
else { else {
lseek(seed_fd, 0, SEEK_SET); lseek(seed_fd, 0, SEEK_SET);
if ((r = loop_write(random_fd, buf, sizeof(buf), false)) != sizeof(buf)) if ((r = loop_write(random_fd, buf, (size_t) r, false)) <= 0)
log_error("Failed to write seed to /dev/random: %s", r < 0 ? strerror(errno) : "short write"); log_error("Failed to write seed to /dev/random: %s", r < 0 ? strerror(errno) : "short write");
} }
...@@ -94,10 +112,10 @@ int main(int argc, char *argv[]) { ...@@ -94,10 +112,10 @@ int main(int argc, char *argv[]) {
fchmod(seed_fd, 0600); fchmod(seed_fd, 0600);
fchown(seed_fd, 0, 0); fchown(seed_fd, 0, 0);
if ((r = loop_read(random_fd, buf, sizeof(buf), false)) != sizeof(buf)) if ((r = loop_read(random_fd, buf, buf_size, false)) <= 0)
log_error("Failed to read new seed from /dev/urandom: %s", r < 0 ? strerror(errno) : "EOF"); log_error("Failed to read new seed from /dev/urandom: %s", r < 0 ? strerror(errno) : "EOF");
else { else {
if ((r = loop_write(seed_fd, buf, sizeof(buf), false)) != sizeof(buf)) if ((r = loop_write(seed_fd, buf, (size_t) r, false)) <= 0)
log_error("Failed to write new random seed file: %s", r < 0 ? strerror(errno) : "short write"); log_error("Failed to write new random seed file: %s", r < 0 ? strerror(errno) : "short write");
} }
...@@ -110,5 +128,7 @@ finish: ...@@ -110,5 +128,7 @@ finish:
if (seed_fd >= 0) if (seed_fd >= 0)
close_nointr_nofail(seed_fd); close_nointr_nofail(seed_fd);
free(buf);
return ret; return ret;
} }
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment