diff options
Diffstat (limited to 'src/lib/libc/crypt/arc4random.c')
| -rw-r--r-- | src/lib/libc/crypt/arc4random.c | 47 |
1 files changed, 11 insertions, 36 deletions
diff --git a/src/lib/libc/crypt/arc4random.c b/src/lib/libc/crypt/arc4random.c index 565bfa0333..d42022c455 100644 --- a/src/lib/libc/crypt/arc4random.c +++ b/src/lib/libc/crypt/arc4random.c | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: arc4random.c,v 1.46 2014/07/17 14:30:41 deraadt Exp $ */ | 1 | /* $OpenBSD: arc4random.c,v 1.47 2014/07/18 02:05:55 deraadt Exp $ */ |
| 2 | 2 | ||
| 3 | /* | 3 | /* |
| 4 | * Copyright (c) 1996, David Mazieres <dm@uun.org> | 4 | * Copyright (c) 1996, David Mazieres <dm@uun.org> |
| @@ -52,11 +52,16 @@ | |||
| 52 | #define RSBUFSZ (16*BLOCKSZ) | 52 | #define RSBUFSZ (16*BLOCKSZ) |
| 53 | 53 | ||
| 54 | /* Marked MAP_INHERIT_ZERO, so zero'd out in fork children. */ | 54 | /* Marked MAP_INHERIT_ZERO, so zero'd out in fork children. */ |
| 55 | static struct { | 55 | static struct _rs { |
| 56 | size_t rs_have; /* valid bytes at end of rs_buf */ | 56 | size_t rs_have; /* valid bytes at end of rs_buf */ |
| 57 | size_t rs_count; /* bytes till reseed */ | 57 | size_t rs_count; /* bytes till reseed */ |
| 58 | } *rs; | 58 | } *rs; |
| 59 | 59 | ||
| 60 | static inline void *_rs_allocate(size_t len); | ||
| 61 | static inline void _rs_forkdetect(void); | ||
| 62 | static inline void _rs_forkdetectsetup(struct _rs *buf, size_t len); | ||
| 63 | #include "arc4random.h" | ||
| 64 | |||
| 60 | /* Preserved in fork children. */ | 65 | /* Preserved in fork children. */ |
| 61 | static struct { | 66 | static struct { |
| 62 | chacha_ctx rs_chacha; /* chacha context for random keystream */ | 67 | chacha_ctx rs_chacha; /* chacha context for random keystream */ |
| @@ -65,19 +70,6 @@ static struct { | |||
| 65 | 70 | ||
| 66 | static inline void _rs_rekey(u_char *dat, size_t datlen); | 71 | static inline void _rs_rekey(u_char *dat, size_t datlen); |
| 67 | 72 | ||
| 68 | #ifndef MAP_INHERIT_ZERO | ||
| 69 | static inline void | ||
| 70 | _rs_forkhandler(void) | ||
| 71 | { | ||
| 72 | /* | ||
| 73 | * Race-free because we're running single-threaded in a new | ||
| 74 | * address space, and once allocated rs is never deallocated. | ||
| 75 | */ | ||
| 76 | if (rs) | ||
| 77 | rs->rs_count = 0; | ||
| 78 | } | ||
| 79 | #endif /* MAP_INHERIT_ZERO */ | ||
| 80 | |||
| 81 | static inline void | 73 | static inline void |
| 82 | _rs_init(u_char *buf, size_t n) | 74 | _rs_init(u_char *buf, size_t n) |
| 83 | { | 75 | { |
| @@ -85,19 +77,12 @@ _rs_init(u_char *buf, size_t n) | |||
| 85 | return; | 77 | return; |
| 86 | 78 | ||
| 87 | if (rs == NULL) { | 79 | if (rs == NULL) { |
| 88 | if ((rs = mmap(NULL, sizeof(*rs), PROT_READ|PROT_WRITE, | 80 | if ((rs = _rs_allocate(sizeof(*rs))) == NULL) |
| 89 | MAP_ANON|MAP_PRIVATE, -1, 0)) == MAP_FAILED) | ||
| 90 | abort(); | ||
| 91 | #ifdef MAP_INHERIT_ZERO | ||
| 92 | if (minherit(rs, sizeof(*rs), MAP_INHERIT_ZERO) == -1) | ||
| 93 | abort(); | 81 | abort(); |
| 94 | #else | 82 | _rs_forkdetectsetup(rs, sizeof(*rs)); |
| 95 | _ARC4_ATFORK(_rs_forkhandler); | ||
| 96 | #endif | ||
| 97 | } | 83 | } |
| 98 | if (rsx == NULL) { | 84 | if (rsx == NULL) { |
| 99 | if ((rsx = mmap(NULL, sizeof(*rsx), PROT_READ|PROT_WRITE, | 85 | if ((rsx = _rs_allocate(sizeof(*rsx))) == NULL) |
| 100 | MAP_ANON|MAP_PRIVATE, -1, 0)) == MAP_FAILED) | ||
| 101 | abort(); | 86 | abort(); |
| 102 | } | 87 | } |
| 103 | 88 | ||
| @@ -129,17 +114,7 @@ _rs_stir(void) | |||
| 129 | static inline void | 114 | static inline void |
| 130 | _rs_stir_if_needed(size_t len) | 115 | _rs_stir_if_needed(size_t len) |
| 131 | { | 116 | { |
| 132 | #ifndef MAP_INHERIT_ZERO | 117 | _rs_forkdetect(); |
| 133 | static pid_t _rs_pid = 0; | ||
| 134 | pid_t pid = getpid(); | ||
| 135 | |||
| 136 | /* If a system lacks MAP_INHERIT_ZERO, resort to getpid() */ | ||
| 137 | if (_rs_pid == 0 || _rs_pid != pid) { | ||
| 138 | _rs_pid = pid; | ||
| 139 | if (rs) | ||
| 140 | rs->rs_count = 0; | ||
| 141 | } | ||
| 142 | #endif | ||
| 143 | if (!rs || rs->rs_count <= len) | 118 | if (!rs || rs->rs_count <= len) |
| 144 | _rs_stir(); | 119 | _rs_stir(); |
| 145 | if (rs->rs_count <= len) | 120 | if (rs->rs_count <= len) |
