Greg Kroah-Hartman | b244131 | 2017-11-01 15:07:57 +0100 | [diff] [blame] | 1 | /* SPDX-License-Identifier: GPL-2.0 */ |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 2 | /* |
| 3 | * include/linux/random.h |
| 4 | * |
| 5 | * Include file for the random number generator. |
| 6 | */ |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 7 | #ifndef _LINUX_RANDOM_H |
| 8 | #define _LINUX_RANDOM_H |
| 9 | |
Herbert Xu | 205a525 | 2015-06-09 18:19:39 +0800 | [diff] [blame] | 10 | #include <linux/list.h> |
Daniel Borkmann | 897ece5 | 2015-10-08 01:20:38 +0200 | [diff] [blame] | 11 | #include <linux/once.h> |
| 12 | |
David Howells | 607ca46 | 2012-10-13 10:46:48 +0100 | [diff] [blame] | 13 | #include <uapi/linux/random.h> |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 14 | |
Herbert Xu | 205a525 | 2015-06-09 18:19:39 +0800 | [diff] [blame] | 15 | struct random_ready_callback { |
| 16 | struct list_head list; |
| 17 | void (*func)(struct random_ready_callback *rdy); |
| 18 | struct module *owner; |
| 19 | }; |
| 20 | |
Linus Torvalds | a2080a6 | 2012-07-04 11:16:01 -0400 | [diff] [blame] | 21 | extern void add_device_randomness(const void *, unsigned int); |
Hsin-Yi Wang | 428826f | 2019-08-23 14:24:51 +0800 | [diff] [blame] | 22 | extern void add_bootloader_randomness(const void *, unsigned int); |
Emese Revfy | 38addce | 2016-06-20 20:41:19 +0200 | [diff] [blame] | 23 | |
Vasily Gorbik | 7e756f4 | 2019-05-07 16:28:15 +0200 | [diff] [blame] | 24 | #if defined(LATENT_ENTROPY_PLUGIN) && !defined(__CHECKER__) |
Emese Revfy | 38addce | 2016-06-20 20:41:19 +0200 | [diff] [blame] | 25 | static inline void add_latent_entropy(void) |
| 26 | { |
| 27 | add_device_randomness((const void *)&latent_entropy, |
| 28 | sizeof(latent_entropy)); |
| 29 | } |
| 30 | #else |
| 31 | static inline void add_latent_entropy(void) {} |
| 32 | #endif |
| 33 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 34 | extern void add_input_randomness(unsigned int type, unsigned int code, |
Emese Revfy | 0766f78 | 2016-06-20 20:42:34 +0200 | [diff] [blame] | 35 | unsigned int value) __latent_entropy; |
| 36 | extern void add_interrupt_randomness(int irq, int irq_flags) __latent_entropy; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 37 | |
| 38 | extern void get_random_bytes(void *buf, int nbytes); |
Jason A. Donenfeld | e297a78 | 2017-06-07 19:58:56 -0400 | [diff] [blame] | 39 | extern int wait_for_random_bytes(void); |
Kees Cook | d555352 | 2019-04-19 23:27:05 -0400 | [diff] [blame] | 40 | extern int __init rand_initialize(void); |
Jason A. Donenfeld | 9a47249 | 2018-07-31 21:11:00 +0200 | [diff] [blame] | 41 | extern bool rng_is_initialized(void); |
Herbert Xu | 205a525 | 2015-06-09 18:19:39 +0800 | [diff] [blame] | 42 | extern int add_random_ready_callback(struct random_ready_callback *rdy); |
| 43 | extern void del_random_ready_callback(struct random_ready_callback *rdy); |
Tobin C. Harding | 753d433 | 2018-06-22 09:15:32 +1000 | [diff] [blame] | 44 | extern int __must_check get_random_bytes_arch(void *buf, int nbytes); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 45 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 46 | #ifndef MODULE |
Arjan van de Ven | 5404732 | 2007-02-12 00:55:28 -0800 | [diff] [blame] | 47 | extern const struct file_operations random_fops, urandom_fops; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 48 | #endif |
| 49 | |
Jason A. Donenfeld | c440408 | 2017-01-22 16:34:08 +0100 | [diff] [blame] | 50 | u32 get_random_u32(void); |
| 51 | u64 get_random_u64(void); |
| 52 | static inline unsigned int get_random_int(void) |
| 53 | { |
| 54 | return get_random_u32(); |
| 55 | } |
| 56 | static inline unsigned long get_random_long(void) |
| 57 | { |
| 58 | #if BITS_PER_LONG == 64 |
| 59 | return get_random_u64(); |
| 60 | #else |
| 61 | return get_random_u32(); |
| 62 | #endif |
| 63 | } |
| 64 | |
Rik van Riel | 022c204 | 2017-07-12 14:36:17 -0700 | [diff] [blame] | 65 | /* |
| 66 | * On 64-bit architectures, protect against non-terminated C string overflows |
| 67 | * by zeroing out the first byte of the canary; this leaves 56 bits of entropy. |
| 68 | */ |
| 69 | #ifdef CONFIG_64BIT |
| 70 | # ifdef __LITTLE_ENDIAN |
| 71 | # define CANARY_MASK 0xffffffffffffff00UL |
| 72 | # else /* big endian, 64 bits: */ |
| 73 | # define CANARY_MASK 0x00ffffffffffffffUL |
| 74 | # endif |
| 75 | #else /* 32 bits: */ |
| 76 | # define CANARY_MASK 0xffffffffUL |
| 77 | #endif |
| 78 | |
| 79 | static inline unsigned long get_random_canary(void) |
| 80 | { |
| 81 | unsigned long val = get_random_long(); |
| 82 | |
| 83 | return val & CANARY_MASK; |
| 84 | } |
| 85 | |
Jason A. Donenfeld | da9ba56 | 2017-06-07 20:05:02 -0400 | [diff] [blame] | 86 | /* Calls wait_for_random_bytes() and then calls get_random_bytes(buf, nbytes). |
| 87 | * Returns the result of the call to wait_for_random_bytes. */ |
| 88 | static inline int get_random_bytes_wait(void *buf, int nbytes) |
| 89 | { |
| 90 | int ret = wait_for_random_bytes(); |
Jason A. Donenfeld | da9ba56 | 2017-06-07 20:05:02 -0400 | [diff] [blame] | 91 | get_random_bytes(buf, nbytes); |
Jason A. Donenfeld | 25e3fca | 2018-02-04 23:07:46 +0100 | [diff] [blame] | 92 | return ret; |
Jason A. Donenfeld | da9ba56 | 2017-06-07 20:05:02 -0400 | [diff] [blame] | 93 | } |
| 94 | |
| 95 | #define declare_get_random_var_wait(var) \ |
| 96 | static inline int get_random_ ## var ## _wait(var *out) { \ |
| 97 | int ret = wait_for_random_bytes(); \ |
| 98 | if (unlikely(ret)) \ |
| 99 | return ret; \ |
| 100 | *out = get_random_ ## var(); \ |
| 101 | return 0; \ |
| 102 | } |
| 103 | declare_get_random_var_wait(u32) |
| 104 | declare_get_random_var_wait(u64) |
| 105 | declare_get_random_var_wait(int) |
| 106 | declare_get_random_var_wait(long) |
| 107 | #undef declare_get_random_var |
| 108 | |
Jason Cooper | 99fdafd | 2016-10-11 13:53:52 -0700 | [diff] [blame] | 109 | unsigned long randomize_page(unsigned long start, unsigned long range); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 110 | |
Akinobu Mita | 496f2f9 | 2012-12-17 16:04:23 -0800 | [diff] [blame] | 111 | u32 prandom_u32(void); |
Daniel Borkmann | a98406e | 2014-08-23 17:03:28 +0200 | [diff] [blame] | 112 | void prandom_bytes(void *buf, size_t nbytes); |
Akinobu Mita | 496f2f9 | 2012-12-17 16:04:23 -0800 | [diff] [blame] | 113 | void prandom_seed(u32 seed); |
Hannes Frederic Sowa | 4af712e | 2013-11-11 12:20:34 +0100 | [diff] [blame] | 114 | void prandom_reseed_late(void); |
Stephen Hemminger | aaa248f | 2006-10-17 00:09:42 -0700 | [diff] [blame] | 115 | |
Daniel Borkmann | 38e9efc | 2013-11-11 12:20:35 +0100 | [diff] [blame] | 116 | struct rnd_state { |
Daniel Borkmann | a98814c | 2013-11-11 12:20:36 +0100 | [diff] [blame] | 117 | __u32 s1, s2, s3, s4; |
Daniel Borkmann | 38e9efc | 2013-11-11 12:20:35 +0100 | [diff] [blame] | 118 | }; |
| 119 | |
Daniel Borkmann | a98814c | 2013-11-11 12:20:36 +0100 | [diff] [blame] | 120 | u32 prandom_u32_state(struct rnd_state *state); |
Daniel Borkmann | a98406e | 2014-08-23 17:03:28 +0200 | [diff] [blame] | 121 | void prandom_bytes_state(struct rnd_state *state, void *buf, size_t nbytes); |
Daniel Borkmann | 897ece5 | 2015-10-08 01:20:38 +0200 | [diff] [blame] | 122 | void prandom_seed_full_state(struct rnd_state __percpu *pcpu_state); |
| 123 | |
| 124 | #define prandom_init_once(pcpu_state) \ |
| 125 | DO_ONCE(prandom_seed_full_state, (pcpu_state)) |
Joe Eykholt | 5960164 | 2010-05-26 14:44:13 -0700 | [diff] [blame] | 126 | |
Daniel Borkmann | f337db6 | 2014-01-22 02:29:39 +0100 | [diff] [blame] | 127 | /** |
| 128 | * prandom_u32_max - returns a pseudo-random number in interval [0, ep_ro) |
| 129 | * @ep_ro: right open interval endpoint |
| 130 | * |
| 131 | * Returns a pseudo-random number that is in interval [0, ep_ro). Note |
| 132 | * that the result depends on PRNG being well distributed in [0, ~0U] |
| 133 | * u32 space. Here we use maximally equidistributed combined Tausworthe |
| 134 | * generator, that is, prandom_u32(). This is useful when requesting a |
| 135 | * random index of an array containing ep_ro elements, for example. |
| 136 | * |
| 137 | * Returns: pseudo-random number in interval [0, ep_ro) |
| 138 | */ |
| 139 | static inline u32 prandom_u32_max(u32 ep_ro) |
| 140 | { |
| 141 | return (u32)(((u64) prandom_u32() * ep_ro) >> 32); |
| 142 | } |
| 143 | |
Joe Eykholt | 5960164 | 2010-05-26 14:44:13 -0700 | [diff] [blame] | 144 | /* |
| 145 | * Handle minimum values for seeds |
| 146 | */ |
| 147 | static inline u32 __seed(u32 x, u32 m) |
| 148 | { |
| 149 | return (x < m) ? x + m : x; |
| 150 | } |
| 151 | |
| 152 | /** |
Akinobu Mita | 496f2f9 | 2012-12-17 16:04:23 -0800 | [diff] [blame] | 153 | * prandom_seed_state - set seed for prandom_u32_state(). |
Joe Eykholt | 5960164 | 2010-05-26 14:44:13 -0700 | [diff] [blame] | 154 | * @state: pointer to state structure to receive the seed. |
| 155 | * @seed: arbitrary 64-bit value to use as a seed. |
| 156 | */ |
Akinobu Mita | 496f2f9 | 2012-12-17 16:04:23 -0800 | [diff] [blame] | 157 | static inline void prandom_seed_state(struct rnd_state *state, u64 seed) |
Joe Eykholt | 5960164 | 2010-05-26 14:44:13 -0700 | [diff] [blame] | 158 | { |
| 159 | u32 i = (seed >> 32) ^ (seed << 10) ^ seed; |
| 160 | |
Daniel Borkmann | a98814c | 2013-11-11 12:20:36 +0100 | [diff] [blame] | 161 | state->s1 = __seed(i, 2U); |
| 162 | state->s2 = __seed(i, 8U); |
| 163 | state->s3 = __seed(i, 16U); |
| 164 | state->s4 = __seed(i, 128U); |
Joe Eykholt | 5960164 | 2010-05-26 14:44:13 -0700 | [diff] [blame] | 165 | } |
| 166 | |
H. Peter Anvin | 63d7717 | 2011-07-31 13:54:50 -0700 | [diff] [blame] | 167 | #ifdef CONFIG_ARCH_RANDOM |
| 168 | # include <asm/archrandom.h> |
| 169 | #else |
Richard Henderson | 904caa6 | 2020-01-10 14:54:18 +0000 | [diff] [blame^] | 170 | static inline bool __must_check arch_get_random_long(unsigned long *v) |
H. Peter Anvin | 63d7717 | 2011-07-31 13:54:50 -0700 | [diff] [blame] | 171 | { |
Richard Henderson | 66f5ae8 | 2020-01-10 14:54:17 +0000 | [diff] [blame] | 172 | return false; |
H. Peter Anvin | 63d7717 | 2011-07-31 13:54:50 -0700 | [diff] [blame] | 173 | } |
Richard Henderson | 904caa6 | 2020-01-10 14:54:18 +0000 | [diff] [blame^] | 174 | static inline bool __must_check arch_get_random_int(unsigned int *v) |
H. Peter Anvin | 63d7717 | 2011-07-31 13:54:50 -0700 | [diff] [blame] | 175 | { |
Richard Henderson | 66f5ae8 | 2020-01-10 14:54:17 +0000 | [diff] [blame] | 176 | return false; |
H. Peter Anvin | 63d7717 | 2011-07-31 13:54:50 -0700 | [diff] [blame] | 177 | } |
Richard Henderson | 904caa6 | 2020-01-10 14:54:18 +0000 | [diff] [blame^] | 178 | static inline bool __must_check arch_get_random_seed_long(unsigned long *v) |
H. Peter Anvin | d20f78d | 2014-03-17 16:36:27 -0700 | [diff] [blame] | 179 | { |
Richard Henderson | 66f5ae8 | 2020-01-10 14:54:17 +0000 | [diff] [blame] | 180 | return false; |
H. Peter Anvin | d20f78d | 2014-03-17 16:36:27 -0700 | [diff] [blame] | 181 | } |
Richard Henderson | 904caa6 | 2020-01-10 14:54:18 +0000 | [diff] [blame^] | 182 | static inline bool __must_check arch_get_random_seed_int(unsigned int *v) |
H. Peter Anvin | d20f78d | 2014-03-17 16:36:27 -0700 | [diff] [blame] | 183 | { |
Richard Henderson | 66f5ae8 | 2020-01-10 14:54:17 +0000 | [diff] [blame] | 184 | return false; |
H. Peter Anvin | d20f78d | 2014-03-17 16:36:27 -0700 | [diff] [blame] | 185 | } |
H. Peter Anvin | 63d7717 | 2011-07-31 13:54:50 -0700 | [diff] [blame] | 186 | #endif |
| 187 | |
Tom Herbert | 055dc21 | 2013-01-22 09:49:50 +0000 | [diff] [blame] | 188 | /* Pseudo random number generator from numerical recipes. */ |
| 189 | static inline u32 next_pseudo_random32(u32 seed) |
| 190 | { |
| 191 | return seed * 1664525 + 1013904223; |
| 192 | } |
| 193 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 194 | #endif /* _LINUX_RANDOM_H */ |