diff -Naur linux-2.6.5-orig/drivers/char/Kconfig linux-2.6.5/drivers/char/Kconfig --- linux-2.6.5-orig/drivers/char/Kconfig 2004-05-11 03:25:51.000000000 -0400 +++ linux-2.6.5/drivers/char/Kconfig 2004-05-11 10:21:38.585258766 -0400 @@ -1008,6 +1008,18 @@ out to lunch past a certain margin. It can reboot the system or merely print a warning. +config FRANDOM + tristate "Fast random data generator suite (/dev/frandom and /dev/erandom)" + help + Fast random data/number generator support in kernel. This random + generator is 10-50 times faster than /dev/urandom, and saves kernel + entropy. + + If unsure, say Y unless you're tight on kernel size. This module is + small and harmless otherwise. + + If you choose M, the sysctl interface will be disabled. + endmenu source "drivers/char/lirc/Kconfig" diff -Naur linux-2.6.5-orig/drivers/char/Makefile linux-2.6.5/drivers/char/Makefile --- linux-2.6.5-orig/drivers/char/Makefile 2004-05-11 03:25:51.000000000 -0400 +++ linux-2.6.5/drivers/char/Makefile 2004-05-11 03:30:01.386244722 -0400 @@ -90,6 +90,8 @@ obj-$(CONFIG_HANGCHECK_TIMER) += hangcheck-timer.o +obj-$(CONFIG_FRANDOM) += frandom.o + # Files generated that shall be removed upon make clean clean-files := consolemap_deftbl.c defkeymap.c qtronixmap.c diff -Naur linux-2.6.5-orig/drivers/char/frandom.c linux-2.6.5/drivers/char/frandom.c --- linux-2.6.5-orig/drivers/char/frandom.c 1969-12-31 19:00:00.000000000 -0500 +++ linux-2.6.5/drivers/char/frandom.c 2004-05-11 11:53:31.053012443 -0400 @@ -0,0 +1,366 @@ +/* +** frandom.c +** Fast pseudo-random generator +** +** (c) Copyright 2003 Eli Billauer +** http://www.billauer.co.il +** +** This program is free software; you can redistribute it and/or modify +** it under the terms of the GNU General Public License as published by +** the Free Software Foundation; either version 2 of the License, or +** (at your option) any later version. +** +** Usage: mknod /dev/frandom c 235 11 +** mknod /dev/erandom c 235 12 +** insmod frandom +** +** This code is highly based upon the examples given in the book "Linux +** Device Drivers" by Alessandro Rubini and Jonathan Corbet, published +** by O'Reilly & Associates. +** O'Reilly's release of this book on the web for free is highly +** appreciated. +** +*/ + +#include +#include +#include + +#include +#include +#include +#include +#include +#include +#include + +#include + +#if (LINUX_VERSION_CODE>=KERNEL_VERSION(2,6,0)) +#include +#endif + +#define INTERNAL_SEED 0 +#define EXTERNAL_SEED 1 + +#define FRANDOM_MAJOR 235 +#define FRANDOM_MINOR 11 +#define ERANDOM_MINOR 12 + +static struct file_operations frandom_fops; /* Values assigned below */ + +static int erandom_seeded = 0; /* Internal flag */ + +static int frandom_major = FRANDOM_MAJOR; +static int frandom_minor = FRANDOM_MINOR; +static int erandom_minor = ERANDOM_MINOR; +static int frandom_bufsize = 256; +static int frandom_chunklimit = 0; /* =0 means unlimited */ + +MODULE_DESCRIPTION("Fast pseudo-random number generator"); +MODULE_LICENSE("GPL"); +MODULE_AUTHOR("Eli Billauer"); +MODULE_PARM(frandom_major,"i"); +MODULE_PARM_DESC(frandom_major,"Major number of /dev/frandom and /dev/erandom"); +MODULE_PARM(frandom_minor,"i"); +MODULE_PARM_DESC(frandom_minor,"Minor number of /dev/frandom"); +MODULE_PARM(erandom_minor,"i"); +MODULE_PARM_DESC(erandom_minor,"Minor number of /dev/erandom"); +MODULE_PARM(frandom_bufsize,"i"); +MODULE_PARM_DESC(frandom_bufsize,"Internal buffer size in bytes. Default is 256. Must be >= 256"); +MODULE_PARM(frandom_chunklimit,"i"); +MODULE_PARM_DESC(frandom_chunklimit,"Limit for read() blocks size. 0 (default) is unlimited, otherwise must be >= 256"); + +struct frandom_state +{ + struct semaphore sem; /* Semaphore on the state structure */ + + u8 S[256]; /* The state array */ + u8 i; + u8 j; + + char *buf; +}; + +static struct frandom_state *erandom_state; + +static inline void swap_byte(u8 *a, u8 *b) +{ + u8 swapByte; + + swapByte = *a; + *a = *b; + *b = swapByte; +} + +static void init_rand_state(struct frandom_state *state, int seedflag); + +void erandom_get_random_bytes(char *buf, size_t count) +{ + struct frandom_state *state = erandom_state; + int k; + + unsigned int i; + unsigned int j; + u8 *S; + + /* If we fail to get the semaphore, we revert to external random data. + Since semaphore blocking is expected to be very rare, and interrupts + during these rare and very short periods of time even less frequent, + we take the better-safe-than-sorry approach, and fill the buffer + some expensive random data, in case the caller wasn't aware of this + possibility, and expects random data anyhow. + */ + + if (down_interruptible(&state->sem)) { + get_random_bytes(buf, count); + return; + } + + /* We seed erandom as late as possible, hoping that the kernel's main + RNG is already restored in the boot sequence (not critical, but + better. + */ + + if (!erandom_seeded) { + erandom_seeded = 1; + init_rand_state(state, EXTERNAL_SEED); + printk(KERN_INFO "frandom: Seeded global generator now (used by erandom)\n"); + } + + i = state->i; + j = state->j; + S = state->S; + + for (k=0; ki = i; + state->j = j; + + up(&state->sem); +} + +static void init_rand_state(struct frandom_state *state, int seedflag) +{ + unsigned int i, j, k; + u8 *S; + u8 *seed = state->buf; + + if (seedflag == INTERNAL_SEED) + erandom_get_random_bytes(seed, 256); + else + get_random_bytes(seed, 256); + + S = state->S; + for (i=0; i<256; i++) + *S++=i; + + j=0; + S = state->S; + + for (i=0; i<256; i++) { + j = (j + S[i] + *seed++) & 0xff; + swap_byte(&S[i], &S[j]); + } + + /* It's considered good practice to discard the first 256 bytes + generated. So we do it: + */ + + i=0; j=0; + for (k=0; k<256; k++) { + i = (i + 1) & 0xff; + j = (j + S[i]) & 0xff; + swap_byte(&S[i], &S[j]); + } + + state->i = i; /* Save state */ + state->j = j; +} + +static int frandom_open(struct inode *inode, struct file *filp) +{ + + struct frandom_state *state; + +#if LINUX_VERSION_CODE >= KERNEL_VERSION(2,6,0) + int num =MINOR(inode->i_rdev); +#else + int num =MINOR(kdev_t_to_nr(inode->i_rdev)); +#endif + if ((num != frandom_minor) && (num != erandom_minor)) return -ENODEV; + + state = kmalloc(sizeof(struct frandom_state), GFP_KERNEL); + if (!state) + return -ENOMEM; + + state->buf = kmalloc(frandom_bufsize, GFP_KERNEL); + if (!state->buf) { + kfree(state); + return -ENOMEM; + } + + sema_init(&state->sem, 1); /* Init semaphore as a mutex */ + + if (num == frandom_minor) + init_rand_state(state, EXTERNAL_SEED); + else + init_rand_state(state, INTERNAL_SEED); + + filp->private_data = state; + +#if (LINUX_VERSION_CODEprivate_data; + + kfree(state->buf); + kfree(state); + +#if (LINUX_VERSION_CODEprivate_data; + ssize_t ret; + int dobytes, k; + char *localbuf; + + unsigned int i; + unsigned int j; + u8 *S; + + if (down_interruptible(&state->sem)) + return -ERESTARTSYS; + + if ((frandom_chunklimit > 0) && (count > frandom_chunklimit)) + count = frandom_chunklimit; + + ret = count; /* It's either everything or an error... */ + + i = state->i; + j = state->j; + S = state->S; + + while (count) { + if (count > frandom_bufsize) + dobytes = frandom_bufsize; + else + dobytes = count; + + localbuf = state->buf; + + for (k=0; kbuf, dobytes)) { + ret = -EFAULT; + goto out; + } + + buf += dobytes; + count -= dobytes; + } + + out: + state->i = i; + state->j = j; + + up(&state->sem); + return ret; +} + +static struct file_operations frandom_fops = { + read: frandom_read, + open: frandom_open, + release: frandom_release, +}; + +static void frandom_cleanup_module(void) { + kfree(erandom_state->buf); + kfree(erandom_state); + + unregister_chrdev(frandom_major, "frandom"); +} + + +static int frandom_init_module(void) +{ + int result; + + /* The buffer size MUST be at least 256 bytes, because we assume that + minimal length in init_rand_state(). + */ + if (frandom_bufsize < 256) { + printk(KERN_ERR "frandom: Refused to load because frandom_bufsize=%d < 256\n",frandom_bufsize); + return -EINVAL; + } + if ((frandom_chunklimit != 0) && (frandom_chunklimit < 256)) { + printk(KERN_ERR "frandom: Refused to load because frandom_chunklimit=%d < 256 and != 0\n",frandom_chunklimit); + return -EINVAL; + } + + erandom_state = kmalloc(sizeof(struct frandom_state), GFP_KERNEL); + if (!erandom_state) + return -ENOMEM; + + /* This specific buffer is only used for seeding, so we need + 256 bytes exactly */ + erandom_state->buf = kmalloc(256, GFP_KERNEL); + if (!erandom_state->buf) { + kfree(erandom_state); + return -ENOMEM; + } + + sema_init(&erandom_state->sem, 1); /* Init semaphore as a mutex */ + + erandom_seeded = 0; + +#ifdef SET_MODULE_OWNER + SET_MODULE_OWNER(&frandom_fops); +#endif + /* + * Register your major, and accept a dynamic number. This is the + * first thing to do, in order to avoid releasing other module's + * fops in frandom_cleanup_module() + */ + result = register_chrdev(frandom_major, "frandom", &frandom_fops); + if (result < 0) { + printk(KERN_WARNING "frandom: can't get major %d\n",frandom_major); + + kfree(erandom_state->buf); + kfree(erandom_state); + + return result; + } + if (frandom_major == 0) frandom_major = result; /* dynamic */ + + return 0; /* succeed */ +} + +module_init(frandom_init_module); +module_exit(frandom_cleanup_module); + +EXPORT_SYMBOL(erandom_get_random_bytes); diff -Naur linux-2.6.5-orig/include/linux/sysctl.h linux-2.6.5/include/linux/sysctl.h --- linux-2.6.5-orig/include/linux/sysctl.h 2004-05-11 03:26:16.000000000 -0400 +++ linux-2.6.5/include/linux/sysctl.h 2004-05-11 03:30:51.241392578 -0400 @@ -213,7 +213,8 @@ RANDOM_READ_THRESH=3, RANDOM_WRITE_THRESH=4, RANDOM_BOOT_ID=5, - RANDOM_UUID=6 + RANDOM_UUID=6, + RANDOM_ERANDOM=7, }; /* /proc/sys/kernel/pty */