Skip to content

Commit 0364a34

Browse files
committed
linuxkm/lkcapi_sha_glue.c and linuxkm/linuxkm_wc_port.h: when LINUXKM_DRBG_GET_RANDOM_BYTES, add "-with-global-replace" to the DRBG driver name, to advertise that /dev/[u]random and getrandom() are FIPS PRNGs; when NO_LINUXKM_DRBG_GET_RANDOM_BYTES, don't implicitly define LINUXKM_LKCAPI_REGISTER_HASH_DRBG_DEFAULT.
1 parent 10d4b1d commit 0364a34

2 files changed

Lines changed: 29 additions & 19 deletions

File tree

linuxkm/linuxkm_wc_port.h

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -545,9 +545,10 @@
545545
* to assure that calls to get_random_bytes() in random.c are gated out
546546
* (they would recurse, potentially infinitely).
547547
*/
548-
#if (defined(LINUXKM_LKCAPI_REGISTER_ALL) && \
549-
!defined(LINUXKM_LKCAPI_DONT_REGISTER_HASH_DRBG) && \
550-
!defined(LINUXKM_LKCAPI_DONT_REGISTER_HASH_DRBG_DEFAULT)) && \
548+
#if defined(LINUXKM_LKCAPI_REGISTER_ALL) && \
549+
!defined(LINUXKM_LKCAPI_DONT_REGISTER_HASH_DRBG) && \
550+
!defined(LINUXKM_LKCAPI_DONT_REGISTER_HASH_DRBG_DEFAULT) && \
551+
!defined(NO_LINUXKM_DRBG_GET_RANDOM_BYTES) && \
551552
!defined(LINUXKM_LKCAPI_REGISTER_HASH_DRBG_DEFAULT)
552553
#define LINUXKM_LKCAPI_REGISTER_HASH_DRBG_DEFAULT
553554
#endif

linuxkm/lkcapi_sha_glue.c

Lines changed: 25 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,22 @@
3030
#error SHA* WC_LINUXKM_C_FALLBACK_IN_SHIMS is not currently supported.
3131
#endif
3232

33+
#ifdef NO_LINUXKM_DRBG_GET_RANDOM_BYTES
34+
#undef LINUXKM_DRBG_GET_RANDOM_BYTES
35+
/* setup for LINUXKM_LKCAPI_REGISTER_HASH_DRBG_DEFAULT is in linuxkm_wc_port.h */
36+
#elif defined(LINUXKM_LKCAPI_REGISTER_HASH_DRBG_DEFAULT) && \
37+
(defined(WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS) || \
38+
defined(WOLFSSL_LINUXKM_USE_GET_RANDOM_KPROBES))
39+
#ifndef LINUXKM_DRBG_GET_RANDOM_BYTES
40+
#define LINUXKM_DRBG_GET_RANDOM_BYTES
41+
#endif
42+
#else
43+
#ifdef LINUXKM_DRBG_GET_RANDOM_BYTES
44+
#error LINUXKM_DRBG_GET_RANDOM_BYTES configured with no callback model configured.
45+
#undef LINUXKM_DRBG_GET_RANDOM_BYTES
46+
#endif
47+
#endif
48+
3349
#include <wolfssl/wolfcrypt/sha.h>
3450
#include <wolfssl/wolfcrypt/hmac.h>
3551

@@ -94,7 +110,14 @@
94110
* exhaustion. A caller that really needs PR can pass in seed data in its call
95111
* to our rng_alg.generate() implementation.
96112
*/
97-
#define WOLFKM_STDRNG_DRIVER ("sha2-256-drbg-nopr" WOLFKM_SHA_DRIVER_SUFFIX)
113+
#ifdef LINUXKM_DRBG_GET_RANDOM_BYTES
114+
#define WOLFKM_STDRNG_DRIVER ("sha2-256-drbg-nopr" \
115+
WOLFKM_DRIVER_SUFFIX_BASE \
116+
"-with-global-replace")
117+
#else
118+
#define WOLFKM_STDRNG_DRIVER ("sha2-256-drbg-nopr" \
119+
WOLFKM_DRIVER_SUFFIX_BASE)
120+
#endif
98121

99122
#ifdef LINUXKM_LKCAPI_REGISTER_SHA_ALL
100123
#define LINUXKM_LKCAPI_REGISTER_SHA1
@@ -388,7 +411,7 @@
388411
#else
389412
#if defined(LINUXKM_LKCAPI_REGISTER_ALL_KCONFIG) && defined(CONFIG_CRYPTO_DRBG) && \
390413
!defined(LINUXKM_LKCAPI_DONT_REGISTER_HASH_DRBG)
391-
#error Config conflict: target kernel has CONFIG_CRYPTO_SHA3, but module is missing WOLFSSL_SHA3
414+
#error Config conflict: target kernel has CONFIG_CRYPTO_DRBG, but module is missing HAVE_HASHDRBG
392415
#endif
393416
#undef LINUXKM_LKCAPI_REGISTER_HASH_DRBG
394417
#endif
@@ -1257,20 +1280,6 @@ static struct rng_alg wc_linuxkm_drbg = {
12571280
};
12581281
static int wc_linuxkm_drbg_loaded = 0;
12591282

1260-
#ifdef NO_LINUXKM_DRBG_GET_RANDOM_BYTES
1261-
#undef LINUXKM_DRBG_GET_RANDOM_BYTES
1262-
#elif defined(LINUXKM_LKCAPI_REGISTER_HASH_DRBG_DEFAULT) && \
1263-
(defined(WOLFSSL_LINUXKM_HAVE_GET_RANDOM_CALLBACKS) || defined(WOLFSSL_LINUXKM_USE_GET_RANDOM_KPROBES))
1264-
#ifndef LINUXKM_DRBG_GET_RANDOM_BYTES
1265-
#define LINUXKM_DRBG_GET_RANDOM_BYTES
1266-
#endif
1267-
#else
1268-
#ifdef LINUXKM_DRBG_GET_RANDOM_BYTES
1269-
#error LINUXKM_DRBG_GET_RANDOM_BYTES configured with no callback model configured.
1270-
#undef LINUXKM_DRBG_GET_RANDOM_BYTES
1271-
#endif
1272-
#endif
1273-
12741283
#ifdef LINUXKM_DRBG_GET_RANDOM_BYTES
12751284

12761285
#ifndef WOLFSSL_SMALL_STACK_CACHE

0 commit comments

Comments
 (0)