From nobody Mon Feb 21 08:07:47 2022 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id BDA4919C917A; Mon, 21 Feb 2022 08:07:48 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4K2FKJ02mJz3qJb; Mon, 21 Feb 2022 08:07:47 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1645430868; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=wu4drENgSCorlkSgr2RHDjT4uV97waU5uJwlvhZO8Tk=; b=n95RZIW1YqY10hC2IbZfF4uGggqrT2fyF4RcY37HcBoadmBwMe02qgChJ1aQq/FLgOXQPw guVJvrH1eueVDmwC3iU0LkiTAg9vprzZHhzNvH40oT1692DfvrEueN91s+9nx/fQaGrgoh q51WGiDrhWR7QY3dMgyQoXxBlbxcvTTmRC1Rm/4b0c8ZdLHxKTn4jHWrOxzoikQm9a108j wb8VPgcNy84IvvOPtrQSQSKjSp6KhANKJE2G/YMnVN1RE2VJvK89YPDniU+dlijkzwlhy7 PipoxLw/ApbqVqBzuEIR5lnDvcU1HYR+FzqgeM1+X1FaKk9NP+tso/zn5Whrgw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id A739F4069; Mon, 21 Feb 2022 08:07:47 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 21L87lfa037046; Mon, 21 Feb 2022 08:07:47 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 21L87lbE037045; Mon, 21 Feb 2022 08:07:47 GMT (envelope-from git) Date: Mon, 21 Feb 2022 08:07:47 GMT Message-Id: <202202210807.21L87lbE037045@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: "David E. O'Brien" Subject: git: 39c32c5bca84 - stable/12 - random/ivy: Provide mechanism to read independent seed values from rdrand List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-branches@freebsd.org X-BeenThere: dev-commits-src-branches@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: obrien X-Git-Repository: src X-Git-Refname: refs/heads/stable/12 X-Git-Reftype: branch X-Git-Commit: 39c32c5bca849b022bc3eb68726bdc1388193c75 Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1645430868; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=wu4drENgSCorlkSgr2RHDjT4uV97waU5uJwlvhZO8Tk=; b=nXI+nu0bkPR5DBcEdB3Q7T6sHrnm+abEI1DzdKR1YVup1oAdNMNFdePJzSIUwrkQDqQppc fl2yy9Dn1iuDojedLYcLslgdjeAmsZBQ9xgdTDuR0/Kcc2q5fwDV86CI6ZB0L5wZ89Epv6 jtE4LHEbyxK1c346Cf5gL4G33AFDow/LkRzSlu2mdkcODAIdUDdaUP0BUZjxn/nqtx++tL huQfhuKehyGy7m9+x/NwmPK7IwSgKT1YBbo8u7K20x4lZoIvpee4gc+tYqO7k10LaUhiZS ygP3SjFSPcFK9qXLUtShlpp8EZLkPxHxoOySf+chFrxO9stgx+OQnAGf/maWEQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1645430868; a=rsa-sha256; cv=none; b=CEKymqorrAxmDsRqaDTaIVHfBa07M0WQ8Kg2brgCgXnjlLuiGRx9/S0A9JWveDA+f50Yed CkdP2WIctWl1rroeuto8God1szuqYubFRr3vbyGfrBe+E0E/m9q/FZj/DYg4nRhwHcs5Tc +9QtL1ifAmcEBvfeWwcvD6FYjrvAdn+JgqzfKYXeiHVITnWm5X1NTkUb3gB5+VOk5b2x4q gY0lSghx8VK59+nyu8MkVKm4NuCGmo6dnBFcLrZvvjdXgoiSj94V8orxw5piMBYfdTKkSQ sugNI3X50+E6m1AdYHup/mvjdiwZKi/jbS00UC2WhtjeMRyhXEwGILx2mhtaHQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch stable/12 has been updated by obrien: URL: https://cgit.FreeBSD.org/src/commit/?id=39c32c5bca849b022bc3eb68726bdc1388193c75 commit 39c32c5bca849b022bc3eb68726bdc1388193c75 Author: Conrad Meyer AuthorDate: 2019-11-22 19:30:31 +0000 Commit: David E. O'Brien CommitDate: 2022-02-21 05:56:43 +0000 random/ivy: Provide mechanism to read independent seed values from rdrand On x86 platforms with the intrinsic, rdrand is a deterministic bit generator (AES-CTR) seeded from an entropic source. On x86 platforms with rdseed, it is something closer to the upstream entropic source. (There is more nuance; a block diagram is provided in [1].) On devices with rdrand and without rdseed, there is no good intrinsic for acecssing the good entropic soure directly. However, the DRBG is guaranteed to reseed every 8 kB on these platforms. As a conservative option, on such hardware we can read an extra 7.99kB samples every time we want a sample from an independent seed. As one can imagine, this drastically slows the effective read rate of RDRAND (a factor of 1024 on amd64 and 2048 on ia32). Microbenchmarks on AMD Zen (has RDSEED) show an RDRAND rate of 25 MB/s and Intel Haswell (no RDSEED) show RDRAND of 170 MB/s. This would reduce the read rate on Haswell to ~170 kB/s (at 100% CPU). random(4)'s harvestq thread periodically "feeds" from pure sources in amounts of 128-1024 bytes. On Haswell, enabling this feature increases the CPU time of RDRAND in each "feed" from approximately 0.7-6 µs to 0.7-6 ms. Because there is some performance penalty to this more conservative option, a knob is provided to enable the change. The change does not affect platforms with RDSEED. [1]: https://software.intel.com/en-us/articles/intel-digital-random-number-generator-drng-software-implementation-guide#inpage-nav-4-2 (cherry picked from commit cb285f7c7c5ed93ca01632e839d8d093cb261a9e) --- sys/dev/random/ivy.c | 46 +++++++++++++++++++++++++++++++++++----------- 1 file changed, 35 insertions(+), 11 deletions(-) diff --git a/sys/dev/random/ivy.c b/sys/dev/random/ivy.c index a33e6bb63327..dfb477fe59fb 100644 --- a/sys/dev/random/ivy.c +++ b/sys/dev/random/ivy.c @@ -40,6 +40,7 @@ __FBSDID("$FreeBSD$"); #include #include #include +#include #include #include @@ -59,23 +60,46 @@ static struct random_source random_ivy = { .rs_read = random_ivy_read }; +SYSCTL_NODE(_kern_random, OID_AUTO, rdrand, CTLFLAG_RW, 0, + "rdrand (ivy) entropy source"); +static bool acquire_independent_seed_samples = false; +SYSCTL_BOOL(_kern_random_rdrand, OID_AUTO, rdrand_independent_seed, + CTLFLAG_RWTUN, &acquire_independent_seed_samples, 0, + "If non-zero, use more expensive and slow, but safer, seeded samples " + "where RDSEED is not present."); + static bool x86_rdrand_store(u_long *buf) { - u_long rndval; + u_long rndval, seed_iterations, i; int retry; - retry = RETRY_COUNT; - __asm __volatile( - "1:\n\t" - "rdrand %1\n\t" /* read randomness into rndval */ - "jc 2f\n\t" /* CF is set on success, exit retry loop */ - "dec %0\n\t" /* otherwise, retry-- */ - "jne 1b\n\t" /* and loop if retries are not exhausted */ - "2:" - : "+r" (retry), "=r" (rndval) : : "cc"); + /* Per [1], "§ 5.2.6 Generating Seeds from RDRAND," + * machines lacking RDSEED will guarantee RDRAND is reseeded every 8kB + * of generated output. + * + * [1]: https://software.intel.com/en-us/articles/intel-digital-random-number-generator-drng-software-implementation-guide#inpage-nav-6-8 + */ + if (acquire_independent_seed_samples) + seed_iterations = 8 * 1024 / sizeof(*buf); + else + seed_iterations = 1; + + for (i = 0; i < seed_iterations; i++) { + retry = RETRY_COUNT; + __asm __volatile( + "1:\n\t" + "rdrand %1\n\t" /* read randomness into rndval */ + "jc 2f\n\t" /* CF is set on success, exit retry loop */ + "dec %0\n\t" /* otherwise, retry-- */ + "jne 1b\n\t" /* and loop if retries are not exhausted */ + "2:" + : "+r" (retry), "=r" (rndval) : : "cc"); + if (retry == 0) + return (false); + } *buf = rndval; - return (retry != 0); + return (true); } static bool