2011-03-30 12:46:40 +00:00
|
|
|
#include "u.h"
|
|
|
|
#include "../port/lib.h"
|
|
|
|
#include "mem.h"
|
|
|
|
#include "dat.h"
|
|
|
|
#include "fns.h"
|
|
|
|
#include "../port/error.h"
|
|
|
|
|
2016-08-27 18:42:31 +00:00
|
|
|
#include <libsec.h>
|
|
|
|
|
|
|
|
/* machine specific hardware random number generator */
|
|
|
|
void (*hwrandbuf)(void*, ulong) = nil;
|
|
|
|
|
|
|
|
static struct
|
2011-03-30 12:46:40 +00:00
|
|
|
{
|
|
|
|
QLock;
|
2016-08-27 18:42:31 +00:00
|
|
|
Chachastate;
|
|
|
|
} *rs;
|
|
|
|
|
|
|
|
typedef struct Seedbuf Seedbuf;
|
|
|
|
struct Seedbuf
|
2011-03-30 12:46:40 +00:00
|
|
|
{
|
2016-08-27 18:42:31 +00:00
|
|
|
ulong randomcount;
|
|
|
|
uchar buf[64];
|
|
|
|
uchar nbuf;
|
|
|
|
uchar next;
|
|
|
|
ushort bits;
|
2011-03-30 12:46:40 +00:00
|
|
|
|
2016-08-27 18:42:31 +00:00
|
|
|
SHA2_512state ds;
|
|
|
|
};
|
2011-03-30 12:46:40 +00:00
|
|
|
|
2016-08-27 18:42:31 +00:00
|
|
|
static void
|
|
|
|
randomsample(Ureg*, Timer *t)
|
2011-03-30 12:46:40 +00:00
|
|
|
{
|
2016-08-27 18:42:31 +00:00
|
|
|
Seedbuf *s = t->ta;
|
|
|
|
|
|
|
|
if(s->randomcount == 0 || s->nbuf >= sizeof(s->buf))
|
|
|
|
return;
|
|
|
|
s->bits = (s->bits<<2) ^ s->randomcount;
|
|
|
|
s->randomcount = 0;
|
|
|
|
if(++s->next < 8/2)
|
|
|
|
return;
|
|
|
|
s->next = 0;
|
|
|
|
s->buf[s->nbuf++] ^= s->bits;
|
2011-03-30 12:46:40 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
static void
|
2016-08-27 18:42:31 +00:00
|
|
|
randomseed(void*)
|
2011-03-30 12:46:40 +00:00
|
|
|
{
|
2016-08-27 18:42:31 +00:00
|
|
|
Seedbuf *s;
|
|
|
|
|
|
|
|
s = secalloc(sizeof(Seedbuf));
|
2011-03-30 12:46:40 +00:00
|
|
|
|
2016-08-27 18:42:31 +00:00
|
|
|
if(hwrandbuf != nil)
|
|
|
|
(*hwrandbuf)(s->buf, sizeof(s->buf));
|
|
|
|
|
|
|
|
/* Frequency close but not equal to HZ */
|
|
|
|
up->tns = (vlong)(MS2HZ+3)*1000000LL;
|
|
|
|
up->tmode = Tperiodic;
|
|
|
|
up->tt = nil;
|
|
|
|
up->ta = s;
|
|
|
|
up->tf = randomsample;
|
|
|
|
timeradd(up);
|
|
|
|
while(s->nbuf < sizeof(s->buf)){
|
|
|
|
if(++s->randomcount <= 100000)
|
2013-11-22 21:28:20 +00:00
|
|
|
continue;
|
2011-03-30 12:46:40 +00:00
|
|
|
if(anyhigher())
|
|
|
|
sched();
|
|
|
|
}
|
2016-08-27 18:42:31 +00:00
|
|
|
timerdel(up);
|
2011-03-30 12:46:40 +00:00
|
|
|
|
2016-08-27 18:42:31 +00:00
|
|
|
sha2_512(s->buf, sizeof(s->buf), s->buf, &s->ds);
|
|
|
|
setupChachastate(rs, s->buf, 32, s->buf+32, 12, 20);
|
|
|
|
qunlock(rs);
|
2011-03-30 12:46:40 +00:00
|
|
|
|
2016-08-27 18:42:31 +00:00
|
|
|
secfree(s);
|
2011-03-30 12:46:40 +00:00
|
|
|
|
2016-08-27 18:42:31 +00:00
|
|
|
pexit("", 1);
|
2011-03-30 12:46:40 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
void
|
|
|
|
randominit(void)
|
|
|
|
{
|
2016-08-27 18:42:31 +00:00
|
|
|
rs = secalloc(sizeof(*rs));
|
|
|
|
qlock(rs); /* randomseed() unlocks once seeded */
|
|
|
|
kproc("randomseed", randomseed, nil);
|
2011-03-30 12:46:40 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
ulong
|
2016-09-11 00:09:07 +00:00
|
|
|
randomread(void *p, ulong n)
|
2011-03-30 12:46:40 +00:00
|
|
|
{
|
2016-09-11 00:09:07 +00:00
|
|
|
Chachastate c;
|
|
|
|
|
2016-08-27 18:42:31 +00:00
|
|
|
if(n == 0)
|
|
|
|
return 0;
|
2011-03-30 12:46:40 +00:00
|
|
|
|
2016-08-27 18:42:31 +00:00
|
|
|
if(hwrandbuf != nil)
|
2016-09-11 00:09:07 +00:00
|
|
|
(*hwrandbuf)(p, n);
|
2011-03-30 12:46:40 +00:00
|
|
|
|
2016-09-11 17:07:17 +00:00
|
|
|
/* copy chacha state, rekey and increment iv */
|
2016-08-27 18:42:31 +00:00
|
|
|
qlock(rs);
|
2016-09-11 00:09:07 +00:00
|
|
|
c = *rs;
|
2016-09-11 17:07:17 +00:00
|
|
|
chacha_encrypt((uchar*)&rs->input[4], 32, &c);
|
2016-09-11 01:18:48 +00:00
|
|
|
if(++rs->input[13] == 0)
|
|
|
|
if(++rs->input[14] == 0)
|
|
|
|
++rs->input[15];
|
2016-08-27 18:42:31 +00:00
|
|
|
qunlock(rs);
|
2016-09-11 00:09:07 +00:00
|
|
|
|
|
|
|
/* encrypt the buffer, can fault */
|
|
|
|
chacha_encrypt((uchar*)p, n, &c);
|
|
|
|
|
|
|
|
/* prevent state leakage */
|
|
|
|
memset(&c, 0, sizeof(c));
|
2011-03-30 12:46:40 +00:00
|
|
|
|
|
|
|
return n;
|
|
|
|
}
|
2016-09-11 00:09:07 +00:00
|
|
|
|
|
|
|
/* used by fastrand() */
|
|
|
|
void
|
|
|
|
genrandom(uchar *p, int n)
|
|
|
|
{
|
|
|
|
randomread(p, n);
|
|
|
|
}
|
2016-09-11 00:10:25 +00:00
|
|
|
|
|
|
|
/* used by rand(),nrand() */
|
|
|
|
long
|
|
|
|
lrand(void)
|
|
|
|
{
|
|
|
|
/* xoroshiro128+ algorithm */
|
|
|
|
static int seeded = 0;
|
|
|
|
static uvlong s[2];
|
|
|
|
static Lock lk;
|
|
|
|
ulong r;
|
|
|
|
|
|
|
|
if(seeded == 0){
|
|
|
|
randomread(s, sizeof(s));
|
|
|
|
seeded = (s[0] | s[1]) != 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
lock(&lk);
|
|
|
|
r = (s[0] + s[1]) >> 33;
|
|
|
|
s[1] ^= s[0];
|
|
|
|
s[0] = (s[0] << 55 | s[0] >> 9) ^ s[1] ^ (s[1] << 14);
|
|
|
|
s[1] = (s[1] << 36 | s[1] >> 28);
|
|
|
|
unlock(&lk);
|
|
|
|
|
|
|
|
return r;
|
|
|
|
}
|