| From 4e00b339e264802851aff8e73cde7d24b57b18ce Mon Sep 17 00:00:00 2001 |
| From: Theodore Ts'o <tytso@mit.edu> |
| Date: Wed, 25 Apr 2018 01:12:32 -0400 |
| Subject: random: rate limit unseeded randomness warnings |
| |
| From: Theodore Ts'o <tytso@mit.edu> |
| |
| commit 4e00b339e264802851aff8e73cde7d24b57b18ce upstream. |
| |
| On systems without sufficient boot randomness, no point spamming dmesg. |
| |
| Signed-off-by: Theodore Ts'o <tytso@mit.edu> |
| Cc: stable@vger.kernel.org |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| |
| --- |
| drivers/char/random.c | 39 ++++++++++++++++++++++++++++++++++----- |
| 1 file changed, 34 insertions(+), 5 deletions(-) |
| |
| --- a/drivers/char/random.c |
| +++ b/drivers/char/random.c |
| @@ -261,6 +261,7 @@ |
| #include <linux/ptrace.h> |
| #include <linux/workqueue.h> |
| #include <linux/irq.h> |
| +#include <linux/ratelimit.h> |
| #include <linux/syscalls.h> |
| #include <linux/completion.h> |
| #include <linux/uuid.h> |
| @@ -438,6 +439,16 @@ static void _crng_backtrack_protect(stru |
| static void process_random_ready_list(void); |
| static void _get_random_bytes(void *buf, int nbytes); |
| |
| +static struct ratelimit_state unseeded_warning = |
| + RATELIMIT_STATE_INIT("warn_unseeded_randomness", HZ, 3); |
| +static struct ratelimit_state urandom_warning = |
| + RATELIMIT_STATE_INIT("warn_urandom_randomness", HZ, 3); |
| + |
| +static int ratelimit_disable __read_mostly; |
| + |
| +module_param_named(ratelimit_disable, ratelimit_disable, int, 0644); |
| +MODULE_PARM_DESC(ratelimit_disable, "Disable random ratelimit suppression"); |
| + |
| /********************************************************************** |
| * |
| * OS independent entropy store. Here are the functions which handle |
| @@ -931,6 +942,18 @@ static void crng_reseed(struct crng_stat |
| process_random_ready_list(); |
| wake_up_interruptible(&crng_init_wait); |
| pr_notice("random: crng init done\n"); |
| + if (unseeded_warning.missed) { |
| + pr_notice("random: %d get_random_xx warning(s) missed " |
| + "due to ratelimiting\n", |
| + unseeded_warning.missed); |
| + unseeded_warning.missed = 0; |
| + } |
| + if (urandom_warning.missed) { |
| + pr_notice("random: %d urandom warning(s) missed " |
| + "due to ratelimiting\n", |
| + urandom_warning.missed); |
| + urandom_warning.missed = 0; |
| + } |
| } |
| } |
| |
| @@ -1574,8 +1597,9 @@ static void _warn_unseeded_randomness(co |
| #ifndef CONFIG_WARN_ALL_UNSEEDED_RANDOM |
| print_once = true; |
| #endif |
| - pr_notice("random: %s called from %pS with crng_init=%d\n", |
| - func_name, caller, crng_init); |
| + if (__ratelimit(&unseeded_warning)) |
| + pr_notice("random: %s called from %pS with crng_init=%d\n", |
| + func_name, caller, crng_init); |
| } |
| |
| /* |
| @@ -1769,6 +1793,10 @@ static int rand_initialize(void) |
| init_std_data(&blocking_pool); |
| crng_initialize(&primary_crng); |
| crng_global_init_time = jiffies; |
| + if (ratelimit_disable) { |
| + urandom_warning.interval = 0; |
| + unseeded_warning.interval = 0; |
| + } |
| return 0; |
| } |
| early_initcall(rand_initialize); |
| @@ -1836,9 +1864,10 @@ urandom_read(struct file *file, char __u |
| |
| if (!crng_ready() && maxwarn > 0) { |
| maxwarn--; |
| - printk(KERN_NOTICE "random: %s: uninitialized urandom read " |
| - "(%zd bytes read)\n", |
| - current->comm, nbytes); |
| + if (__ratelimit(&urandom_warning)) |
| + printk(KERN_NOTICE "random: %s: uninitialized " |
| + "urandom read (%zd bytes read)\n", |
| + current->comm, nbytes); |
| spin_lock_irqsave(&primary_crng.lock, flags); |
| crng_init_cnt = 0; |
| spin_unlock_irqrestore(&primary_crng.lock, flags); |