看板FB_security
标 题Re: Collecting entropy from device_attach() times.
发信站NCTU CS FreeBSD Server (Fri Sep 21 17:09:56 2012)
转信站ptt!csnews.cs.nctu!news.cs.nctu!FreeBSD.cs.nctu!freebsd.org!owner-free
--lrZ03NoBR/3+SXJZ
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Thu, Sep 20, 2012 at 11:08:15PM -0700, David O'Brien wrote:
> On Fri, Sep 21, 2012 at 07:35:49AM +0200, Pawel Jakub Dawidek wrote:
> > Note that adding sysctl to turn off entropy harvesting from
> > device_attach() is pretty useless, as sysctls can be changed once we
> > start userland and then all device_attach() are already called (modulo
> > drivers loaded later).
>=20
> That is what I had in mind -- .ko drivers loaded post 'initrandom'.
>=20
> The same could be said for kern.random.sys.harvest.interrupt.
> By the time kern.random.sys.harvest.interrupt can be turned off,
> my test system has already processed 784 'origin interrupt' queue
> entries and went from kern.random.sys.seeded=3D0->1.
Yes, this is exactly why I'd like to see corresponding tunable for all
those sysctls.
--=20
Pawel Jakub Dawidek
http://www.wheelsystems.com
FreeBSD committer
http://www.FreeBSD.org
Am I Evil? Yes, I Am!
http://tupytaj.pl
--lrZ03NoBR/3+SXJZ
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (FreeBSD)
iEYEARECAAYFAlBcEsQACgkQForvXbEpPzStFACeOALT31CDBZgi3wA843QKK+NQ
NaQAnRmjjgU+Zv70L/H+FG9pPz682eOf
=Bqar
-----END PGP SIGNATURE-----
--lrZ03NoBR/3+SXJZ--