android_kernel_motorola_sm6375/include
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jason A. Donenfeld c8b06c9242
UPSTREAM: random: split initialization into early step and later step
The full RNG initialization relies on some timestamps, made possible
with initialization functions like time_init() and timekeeping_init().
However, these are only available rather late in initialization.
Meanwhile, other things, such as memory allocator functions, make use of
the RNG much earlier.

So split RNG initialization into two phases. We can provide arch
randomness very early on, and then later, after timekeeping and such are
available, initialize the rest.

This ensures that, for example, slabs are properly randomized if RDRAND
is available. Without this, CONFIG_SLAB_FREELIST_RANDOM=y loses a degree
of its security, because its random seed is potentially deterministic,
since it hasn't yet incorporated RDRAND. It also makes it possible to
use a better seed in kfence, which currently relies on only the cycle
counter.

Another positive consequence is that on systems with RDRAND, running
with CONFIG_WARN_ALL_UNSEEDED_RANDOM=y results in no warnings at all.

One subtle side effect of this change is that on systems with no RDRAND,
RDTSC is now only queried by random_init() once, committing the moment
of the function call, instead of multiple times as before. This is
intentional, as the multiple RDTSCs in a loop before weren't
accomplishing very much, with jitter being better provided by
try_to_generate_entropy(). Plus, filling blocks with RDTSC is still
being done in extract_entropy(), which is necessarily called before
random bytes are served anyway.

Cc: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Kees Cook <keescook@chromium.org>
Reviewed-by: Dominik Brodowski <linux@dominikbrodowski.net>
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
(cherry picked from commit f62384995e4cb7703e5295779c44135c5311770d)
Change-Id: Ibf5ca2ddea8d853c108c6191803046cae8808dfa
[dereference23: Backport to 5.4]
Signed-off-by: Alexander Winkowski <dereference23@outlook.com>
2026-05-07 17:24:10 +03:00
..
acpi ACPICA: Avoid sequence overread in call to strncmp() 2025-06-27 11:02:52 +01:00
asm-generic UPSTREAM: seccomp: Use -1 marker for end of mode 1 syscall list 2026-05-07 10:17:17 -04:00
clocksource
crypto UPSTREAM: crypto: poly1305 - fix poly1305_core_setkey() declaration 2025-09-24 12:16:39 +02:00
drm This is the 5.4.296 stable release 2025-07-18 10:57:54 +00:00
dt-bindings
keys
kvm
linux UPSTREAM: random: split initialization into early step and later step 2026-05-07 17:24:10 +03:00
math-emu
media
misc
net Revert "wifi: cfg80211: Increase akm_suites array size in" 2026-05-05 20:02:19 +03:00
pcmcia
ras
rdma This is the 5.4.296 stable release 2025-07-18 10:57:54 +00:00
scsi This is the 5.4.301 stable release 2025-10-30 07:52:10 +00:00
soc
sound Merge adc52e1422 on remote branch 2025-10-30 10:55:43 -07:00
target
trace FROMGIT: tracing: add error_report_end trace point 2026-05-07 17:24:05 +03:00
uapi UPSTREAM: net: retrieve netns cookie via getsocketopt 2026-05-07 10:18:28 -04:00
vdso
video
xen
OWNERS