summaryrefslogtreecommitdiff
path: root/util/libreboot-utils/lib/rand.c
blob: 5c6cc5622844c02bd44b0259fc5dece7c53eb3f4 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
/* SPDX-License-Identifier: MIT
 * Copyright (c) 2026 Leah Rowe <leah@libreboot.org>
 *
 * Random number generation
 */

#ifndef RAND_H
#define RAND_H

#ifdef __OpenBSD__
#include <sys/param.h>
#endif
#include <sys/types.h>

#ifndef USE_URANDOM
#define USE_URANDOM 0
#endif

#include <errno.h>
#if defined(USE_URANDOM) && \
    ((USE_URANDOM) > 0)
#include <fcntl.h> /* if not arc4random: /dev/urandom */
#endif

#include <fcntl.h>
#include <limits.h>
#include <stddef.h>
#include <string.h>
#include <unistd.h>
#include <stdlib.h>
#include <string.h>

#include "../include/common.h"

/* Regarding Linux getrandom/urandom:
 *
 * For maximum security guarantee, we *only*
 * use getrandom via syscall, or /dev/urandom;
 * use of urandom is ill advised. This is why
 * we use the syscall, in case the libc version
 * of getrandom() might defer to /dev/urandom
 *
 * We *abort* on error, for both /dev/urandom
 * and getrandom(), because the BSD arc4random
 * never returns with error; therefore, for the
 * most parity in terms of behaviour, we abort,
 * because otherwise the function would have two
 * return modes: always successful (BSD), or only
 * sometimes (Linux). The BSD arc4random could
 * theoretically abort; it is extremely unlikely
 * there, and just so on Linux, hence this design.
 *
 * This is important, because cryptographic code
 * for example must not rely on weak randomness.
 * We must therefore treat broken randomness as
 * though the world is broken, and burn accordingly.
 */

void
rset(void *buf, size_t n)
{
	int saved_errno = errno;

	if (if_err(buf == NULL, EFAULT))
		goto err;

#if (defined(__OpenBSD__) || defined(__FreeBSD__) || \
    defined(__NetBSD__) || defined(__APPLE__) || \
    defined(__DragonFly__)) && !(defined(USE_URANDOM) && \
    ((USE_URANDOM) > 0))

	arc4random_buf(buf, n);
	goto out;
#else
	size_t off = 0;
	ssize_t rc = 0;

#if defined(USE_URANDOM) && \
    ((USE_URANDOM) > 0)
	int fd = -1;

	if ((fd = open("/dev/urandom", O_RDONLY)) < 0)
		goto err;
retry_rand:
	if ((rc = read(fd, (unsigned char *)buf + off, n - off)) < 0) {
#elif defined(__linux__)
retry_rand:
	if ((rc = (ssize_t)syscall(SYS_getrandom,
	    (unsigned char *)buf + off, n - off, 0)) < 0) {
#else
#error Unsupported operating system (possibly unsecure randomisation)
#endif
		if (errno == EINTR ||
		    errno == EAGAIN)
			goto retry_rand;

		goto err; /* possibly unsupported by kernel */
	}

	if (rc == 0)
		goto err; /* prevent infinite loop on fatal err */

	if ((off += (size_t)rc) < n)
		goto retry_rand;

#if defined(USE_URANDOM) && \
    ((USE_URANDOM) > 0)
	close_no_err(&fd);
#endif
	goto out;
#endif
out:
	errno = saved_errno;
	return;
err:
	err_no_cleanup(1, ECANCELED,
	    "Randomisation failure, possibly unsupported in your kernel");
	exit(EXIT_FAILURE);
}
#endif