xref: /freebsd/sys/dev/random/randomdev.c (revision db488e4f52a8644bf5d0f6727367b08e18b729ee)
14db9ae91SMark Murray /*-
2095db7e6SConrad Meyer  * Copyright (c) 2017 Oliver Pinter
3d1b06863SMark Murray  * Copyright (c) 2000-2015 Mark R V Murray
44db9ae91SMark Murray  * All rights reserved.
54db9ae91SMark Murray  *
64db9ae91SMark Murray  * Redistribution and use in source and binary forms, with or without
74db9ae91SMark Murray  * modification, are permitted provided that the following conditions
84db9ae91SMark Murray  * are met:
94db9ae91SMark Murray  * 1. Redistributions of source code must retain the above copyright
104db9ae91SMark Murray  *    notice, this list of conditions and the following disclaimer
114db9ae91SMark Murray  *    in this position and unchanged.
124db9ae91SMark Murray  * 2. Redistributions in binary form must reproduce the above copyright
134db9ae91SMark Murray  *    notice, this list of conditions and the following disclaimer in the
144db9ae91SMark Murray  *    documentation and/or other materials provided with the distribution.
154db9ae91SMark Murray  *
164db9ae91SMark Murray  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
174db9ae91SMark Murray  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
184db9ae91SMark Murray  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
194db9ae91SMark Murray  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
204db9ae91SMark Murray  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
214db9ae91SMark Murray  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
224db9ae91SMark Murray  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
234db9ae91SMark Murray  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
244db9ae91SMark Murray  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
254db9ae91SMark Murray  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
264db9ae91SMark Murray  *
274db9ae91SMark Murray  */
284db9ae91SMark Murray 
29aad970f1SDavid E. O'Brien #include <sys/cdefs.h>
30aad970f1SDavid E. O'Brien __FBSDID("$FreeBSD$");
31aad970f1SDavid E. O'Brien 
324db9ae91SMark Murray #include <sys/param.h>
334db9ae91SMark Murray #include <sys/systm.h>
34fb919e4dSMark Murray #include <sys/bus.h>
354db9ae91SMark Murray #include <sys/conf.h>
364db9ae91SMark Murray #include <sys/fcntl.h>
37fb919e4dSMark Murray #include <sys/filio.h>
384db9ae91SMark Murray #include <sys/kernel.h>
3902c986abSMark Murray #include <sys/kthread.h>
40fb919e4dSMark Murray #include <sys/lock.h>
4141ee9f1cSPoul-Henning Kamp #include <sys/module.h>
4210cb2424SMark Murray #include <sys/malloc.h>
43d1b06863SMark Murray #include <sys/poll.h>
44b40ce416SJulian Elischer #include <sys/proc.h>
45f02e47dcSMark Murray #include <sys/random.h>
46d1b06863SMark Murray #include <sys/sbuf.h>
47d1b06863SMark Murray #include <sys/selinfo.h>
4810cb2424SMark Murray #include <sys/sysctl.h>
4910cb2424SMark Murray #include <sys/systm.h>
50fb919e4dSMark Murray #include <sys/uio.h>
5102c986abSMark Murray #include <sys/unistd.h>
524db9ae91SMark Murray 
53d1b06863SMark Murray #include <crypto/rijndael/rijndael-api-fst.h>
547a3f5d11SAllan Jude #include <crypto/sha2/sha256.h>
55d1b06863SMark Murray 
56d1b06863SMark Murray #include <dev/random/hash.h>
5702c986abSMark Murray #include <dev/random/randomdev.h>
58095ed2c9SMark Murray #include <dev/random/random_harvestq.h>
594db9ae91SMark Murray 
603aa77530SMark Murray #define	RANDOM_UNIT	0
61e7806b4cSMark Murray 
62646041a8SMark Murray #if defined(RANDOM_LOADABLE)
63646041a8SMark Murray #define READ_RANDOM_UIO	_read_random_uio
64646041a8SMark Murray #define READ_RANDOM	_read_random
65646041a8SMark Murray static int READ_RANDOM_UIO(struct uio *, bool);
66646041a8SMark Murray static u_int READ_RANDOM(void *, u_int);
67646041a8SMark Murray #else
68646041a8SMark Murray #define READ_RANDOM_UIO	read_random_uio
69646041a8SMark Murray #define READ_RANDOM	read_random
70646041a8SMark Murray #endif
71646041a8SMark Murray 
72d1b06863SMark Murray static d_read_t randomdev_read;
73d1b06863SMark Murray static d_write_t randomdev_write;
74d1b06863SMark Murray static d_poll_t randomdev_poll;
7510cb2424SMark Murray static d_ioctl_t randomdev_ioctl;
764db9ae91SMark Murray 
774db9ae91SMark Murray static struct cdevsw random_cdevsw = {
787ac40f5fSPoul-Henning Kamp 	.d_name = "random",
7910cb2424SMark Murray 	.d_version = D_VERSION,
80d1b06863SMark Murray 	.d_read = randomdev_read,
81d1b06863SMark Murray 	.d_write = randomdev_write,
82d1b06863SMark Murray 	.d_poll = randomdev_poll,
8310cb2424SMark Murray 	.d_ioctl = randomdev_ioctl,
844db9ae91SMark Murray };
854db9ae91SMark Murray 
864db9ae91SMark Murray /* For use with make_dev(9)/destroy_dev(9). */
8789c9c53dSPoul-Henning Kamp static struct cdev *random_dev;
884db9ae91SMark Murray 
893aa77530SMark Murray static void
903aa77530SMark Murray random_alg_context_ra_init_alg(void *data)
913aa77530SMark Murray {
923aa77530SMark Murray 
93646041a8SMark Murray 	p_random_alg_context = &random_alg_context;
94646041a8SMark Murray 	p_random_alg_context->ra_init_alg(data);
95646041a8SMark Murray #if defined(RANDOM_LOADABLE)
96646041a8SMark Murray 	random_infra_init(READ_RANDOM_UIO, READ_RANDOM);
97646041a8SMark Murray #endif
983aa77530SMark Murray }
993aa77530SMark Murray 
1003aa77530SMark Murray static void
1013aa77530SMark Murray random_alg_context_ra_deinit_alg(void *data)
1023aa77530SMark Murray {
1033aa77530SMark Murray 
104646041a8SMark Murray #if defined(RANDOM_LOADABLE)
105646041a8SMark Murray 	random_infra_uninit();
106646041a8SMark Murray #endif
107646041a8SMark Murray 	p_random_alg_context->ra_deinit_alg(data);
108646041a8SMark Murray 	p_random_alg_context = NULL;
1093aa77530SMark Murray }
1103aa77530SMark Murray 
1113aa77530SMark Murray SYSINIT(random_device, SI_SUB_RANDOM, SI_ORDER_THIRD, random_alg_context_ra_init_alg, NULL);
1123aa77530SMark Murray SYSUNINIT(random_device, SI_SUB_RANDOM, SI_ORDER_THIRD, random_alg_context_ra_deinit_alg, NULL);
1133aa77530SMark Murray 
114d1b06863SMark Murray static struct selinfo rsel;
115d1b06863SMark Murray 
116d1b06863SMark Murray /*
117d1b06863SMark Murray  * This is the read uio(9) interface for random(4).
118d1b06863SMark Murray  */
119d1b06863SMark Murray /* ARGSUSED */
120d1b06863SMark Murray static int
121d1b06863SMark Murray randomdev_read(struct cdev *dev __unused, struct uio *uio, int flags)
122d1b06863SMark Murray {
123707d98feSEd Schouten 
124646041a8SMark Murray 	return (READ_RANDOM_UIO(uio, (flags & O_NONBLOCK) != 0));
125707d98feSEd Schouten }
126707d98feSEd Schouten 
127707d98feSEd Schouten int
128646041a8SMark Murray READ_RANDOM_UIO(struct uio *uio, bool nonblock)
129707d98feSEd Schouten {
130d1b06863SMark Murray 	uint8_t *random_buf;
131dbefaadcSMark Murray 	int error, spamcount;
132b712101cSMark Murray 	ssize_t read_len, total_read, c;
133*db488e4fSConrad Meyer 	/* 16 MiB takes about 0.08 s CPU time on my 2017 AMD Zen CPU */
134*db488e4fSConrad Meyer #define SIGCHK_PERIOD (16 * 1024 * 1024)
135*db488e4fSConrad Meyer 	const size_t sigchk_period = SIGCHK_PERIOD;
136*db488e4fSConrad Meyer 
137*db488e4fSConrad Meyer 	CTASSERT(SIGCHK_PERIOD % PAGE_SIZE == 0);
138*db488e4fSConrad Meyer #undef SIGCHK_PERIOD
139d1b06863SMark Murray 
140d1b06863SMark Murray 	random_buf = malloc(PAGE_SIZE, M_ENTROPY, M_WAITOK);
141646041a8SMark Murray 	p_random_alg_context->ra_pre_read();
142d1b06863SMark Murray 	error = 0;
143dbefaadcSMark Murray 	spamcount = 0;
144dbefaadcSMark Murray 	/* (Un)Blocking logic */
145646041a8SMark Murray 	while (!p_random_alg_context->ra_seeded()) {
146bc41a247SEd Schouten 		if (nonblock) {
147d1b06863SMark Murray 			error = EWOULDBLOCK;
148d1b06863SMark Murray 			break;
149d1b06863SMark Murray 		}
150d1b06863SMark Murray 		/* keep tapping away at the pre-read until we seed/unblock. */
151646041a8SMark Murray 		p_random_alg_context->ra_pre_read();
152dbefaadcSMark Murray 		/* Only bother the console every 10 seconds or so */
153dbefaadcSMark Murray 		if (spamcount == 0)
1543aa77530SMark Murray 			printf("random: %s unblock wait\n", __func__);
155dbefaadcSMark Murray 		spamcount = (spamcount + 1)%100;
156dbefaadcSMark Murray 		error = tsleep(&random_alg_context, PCATCH, "randseed", hz/10);
157eda4aaebSMark Murray 		if (error == ERESTART || error == EINTR)
158dbefaadcSMark Murray 			break;
159d1b06863SMark Murray 	}
160d1b06863SMark Murray 	if (error == 0) {
161646041a8SMark Murray 		read_rate_increment((uio->uio_resid + sizeof(uint32_t))/sizeof(uint32_t));
162b712101cSMark Murray 		total_read = 0;
163d1b06863SMark Murray 		while (uio->uio_resid && !error) {
164b712101cSMark Murray 			read_len = uio->uio_resid;
165b712101cSMark Murray 			/*
166b712101cSMark Murray 			 * Belt-and-braces.
167b712101cSMark Murray 			 * Round up the read length to a crypto block size multiple,
168b712101cSMark Murray 			 * which is what the underlying generator is expecting.
169b712101cSMark Murray 			 * See the random_buf size requirements in the Yarrow/Fortuna code.
170b712101cSMark Murray 			 */
1717b250b1eSPedro F. Giffuni 			read_len = roundup(read_len, RANDOM_BLOCKSIZE);
17295b184a0SMark Murray 			/* Work in chunks page-sized or less */
173b712101cSMark Murray 			read_len = MIN(read_len, PAGE_SIZE);
174646041a8SMark Murray 			p_random_alg_context->ra_read(random_buf, read_len);
175b712101cSMark Murray 			c = MIN(uio->uio_resid, read_len);
176*db488e4fSConrad Meyer 			/*
177*db488e4fSConrad Meyer 			 * uiomove() may yield the CPU before each 'c' bytes
178*db488e4fSConrad Meyer 			 * (up to PAGE_SIZE) are copied out.
179*db488e4fSConrad Meyer 			 */
180d1b06863SMark Murray 			error = uiomove(random_buf, c, uio);
181b712101cSMark Murray 			total_read += c;
182*db488e4fSConrad Meyer 			/*
183*db488e4fSConrad Meyer 			 * Poll for signals every few MBs to avoid very long
184*db488e4fSConrad Meyer 			 * uninterruptible syscalls.
185*db488e4fSConrad Meyer 			 */
186*db488e4fSConrad Meyer 			if (error == 0 && uio->uio_resid != 0 &&
187*db488e4fSConrad Meyer 			    total_read % sigchk_period == 0)
188*db488e4fSConrad Meyer 				error = tsleep_sbt(&random_alg_context, PCATCH,
189*db488e4fSConrad Meyer 				    "randrd", SBT_1NS, 0, C_HARDCLOCK);
190d1b06863SMark Murray 		}
191*db488e4fSConrad Meyer 		if (error == ERESTART || error == EINTR)
192d1b06863SMark Murray 			error = 0;
193d1b06863SMark Murray 	}
194d1b06863SMark Murray 	free(random_buf, M_ENTROPY);
195d1b06863SMark Murray 	return (error);
196d1b06863SMark Murray }
197d1b06863SMark Murray 
198d1b06863SMark Murray /*-
199d1b06863SMark Murray  * Kernel API version of read_random().
200d1b06863SMark Murray  * This is similar to random_alg_read(),
201d1b06863SMark Murray  * except it doesn't interface with uio(9).
202d1b06863SMark Murray  * It cannot assumed that random_buf is a multiple of
203d1b06863SMark Murray  * RANDOM_BLOCKSIZE bytes.
204d1b06863SMark Murray  */
205d1b06863SMark Murray u_int
206646041a8SMark Murray READ_RANDOM(void *random_buf, u_int len)
207d1b06863SMark Murray {
20895b184a0SMark Murray 	u_int read_len;
209d1b06863SMark Murray 	uint8_t local_buf[len + RANDOM_BLOCKSIZE];
210d1b06863SMark Murray 
211d1b06863SMark Murray 	KASSERT(random_buf != NULL, ("No suitable random buffer in %s", __func__));
212646041a8SMark Murray 	p_random_alg_context->ra_pre_read();
213d1b06863SMark Murray 	/* (Un)Blocking logic; if not seeded, return nothing. */
214646041a8SMark Murray 	if (p_random_alg_context->ra_seeded()) {
215646041a8SMark Murray 		read_rate_increment((len + sizeof(uint32_t))/sizeof(uint32_t));
21695b184a0SMark Murray 		if (len > 0) {
217b712101cSMark Murray 			/*
218b712101cSMark Murray 			 * Belt-and-braces.
219b712101cSMark Murray 			 * Round up the read length to a crypto block size multiple,
220b712101cSMark Murray 			 * which is what the underlying generator is expecting.
221b712101cSMark Murray 			 */
2227b250b1eSPedro F. Giffuni 			read_len = roundup(len, RANDOM_BLOCKSIZE);
223646041a8SMark Murray 			p_random_alg_context->ra_read(local_buf, read_len);
224d1b06863SMark Murray 			memcpy(random_buf, local_buf, len);
22595b184a0SMark Murray 		}
226d1b06863SMark Murray 	} else
227d1b06863SMark Murray 		len = 0;
228d1b06863SMark Murray 	return (len);
229d1b06863SMark Murray }
230d1b06863SMark Murray 
231646041a8SMark Murray static __inline void
232646041a8SMark Murray randomdev_accumulate(uint8_t *buf, u_int count)
233646041a8SMark Murray {
234646041a8SMark Murray 	static u_int destination = 0;
235646041a8SMark Murray 	static struct harvest_event event;
236646041a8SMark Murray 	static struct randomdev_hash hash;
237646041a8SMark Murray 	static uint32_t entropy_data[RANDOM_KEYSIZE_WORDS];
238646041a8SMark Murray 	uint32_t timestamp;
239646041a8SMark Murray 	int i;
240646041a8SMark Murray 
241646041a8SMark Murray 	/* Extra timing here is helpful to scrape scheduler jitter entropy */
242646041a8SMark Murray 	randomdev_hash_init(&hash);
243646041a8SMark Murray 	timestamp = (uint32_t)get_cyclecount();
244646041a8SMark Murray 	randomdev_hash_iterate(&hash, &timestamp, sizeof(timestamp));
245646041a8SMark Murray 	randomdev_hash_iterate(&hash, buf, count);
246646041a8SMark Murray 	timestamp = (uint32_t)get_cyclecount();
247646041a8SMark Murray 	randomdev_hash_iterate(&hash, &timestamp, sizeof(timestamp));
248646041a8SMark Murray 	randomdev_hash_finish(&hash, entropy_data);
249646041a8SMark Murray 	explicit_bzero(&hash, sizeof(hash));
250646041a8SMark Murray 	for (i = 0; i < RANDOM_KEYSIZE_WORDS; i += sizeof(event.he_entropy)/sizeof(event.he_entropy[0])) {
251646041a8SMark Murray 		event.he_somecounter = (uint32_t)get_cyclecount();
252646041a8SMark Murray 		event.he_size = sizeof(event.he_entropy);
253646041a8SMark Murray 		event.he_bits = event.he_size/8;
254646041a8SMark Murray 		event.he_source = RANDOM_CACHED;
255646041a8SMark Murray 		event.he_destination = destination++; /* Harmless cheating */
256646041a8SMark Murray 		memcpy(event.he_entropy, entropy_data + i, sizeof(event.he_entropy));
257646041a8SMark Murray 		p_random_alg_context->ra_event_processor(&event);
258646041a8SMark Murray 	}
259646041a8SMark Murray 	explicit_bzero(entropy_data, sizeof(entropy_data));
260646041a8SMark Murray }
261646041a8SMark Murray 
262d1b06863SMark Murray /* ARGSUSED */
263d1b06863SMark Murray static int
264d1b06863SMark Murray randomdev_write(struct cdev *dev __unused, struct uio *uio, int flags __unused)
265d1b06863SMark Murray {
266d1b06863SMark Murray 	uint8_t *random_buf;
267d1b06863SMark Murray 	int c, error = 0;
268d1b06863SMark Murray 	ssize_t nbytes;
269d1b06863SMark Murray 
270d1b06863SMark Murray 	random_buf = malloc(PAGE_SIZE, M_ENTROPY, M_WAITOK);
271d1b06863SMark Murray 	nbytes = uio->uio_resid;
272d1b06863SMark Murray 	while (uio->uio_resid > 0 && error == 0) {
273d1b06863SMark Murray 		c = MIN(uio->uio_resid, PAGE_SIZE);
274d1b06863SMark Murray 		error = uiomove(random_buf, c, uio);
275d1b06863SMark Murray 		if (error)
276d1b06863SMark Murray 			break;
277646041a8SMark Murray 		randomdev_accumulate(random_buf, c);
278d1b06863SMark Murray 		tsleep(&random_alg_context, 0, "randwr", hz/10);
279d1b06863SMark Murray 	}
280d1b06863SMark Murray 	if (nbytes != uio->uio_resid && (error == ERESTART || error == EINTR))
281d1b06863SMark Murray 		/* Partial write, not error. */
282d1b06863SMark Murray 		error = 0;
283d1b06863SMark Murray 	free(random_buf, M_ENTROPY);
284d1b06863SMark Murray 	return (error);
285d1b06863SMark Murray }
286d1b06863SMark Murray 
287d1b06863SMark Murray /* ARGSUSED */
288d1b06863SMark Murray static int
289d1b06863SMark Murray randomdev_poll(struct cdev *dev __unused, int events, struct thread *td __unused)
290d1b06863SMark Murray {
291d1b06863SMark Murray 
292d1b06863SMark Murray 	if (events & (POLLIN | POLLRDNORM)) {
293646041a8SMark Murray 		if (p_random_alg_context->ra_seeded())
294d1b06863SMark Murray 			events &= (POLLIN | POLLRDNORM);
295d1b06863SMark Murray 		else
296d1b06863SMark Murray 			selrecord(td, &rsel);
297d1b06863SMark Murray 	}
298d1b06863SMark Murray 	return (events);
299d1b06863SMark Murray }
300d1b06863SMark Murray 
301d1b06863SMark Murray /* This will be called by the entropy processor when it seeds itself and becomes secure */
302d1b06863SMark Murray void
303d1b06863SMark Murray randomdev_unblock(void)
304d1b06863SMark Murray {
305d1b06863SMark Murray 
306d1b06863SMark Murray 	selwakeuppri(&rsel, PUSER);
307d1b06863SMark Murray 	wakeup(&random_alg_context);
308d1b06863SMark Murray 	printf("random: unblocking device.\n");
309d1b06863SMark Murray 	/* Do random(9) a favour while we are about it. */
310d1b06863SMark Murray 	(void)atomic_cmpset_int(&arc4rand_iniseed_state, ARC4_ENTR_NONE, ARC4_ENTR_HAVE);
311d1b06863SMark Murray }
312d1b06863SMark Murray 
313e1199601SMark Murray /* ARGSUSED */
3144db9ae91SMark Murray static int
31510cb2424SMark Murray randomdev_ioctl(struct cdev *dev __unused, u_long cmd, caddr_t addr __unused,
316e1199601SMark Murray     int flags __unused, struct thread *td __unused)
3174d87a031SMark Murray {
318e7806b4cSMark Murray 	int error = 0;
319e7806b4cSMark Murray 
32041bc9751SMark Murray 	switch (cmd) {
32141bc9751SMark Murray 		/* Really handled in upper layer */
32241bc9751SMark Murray 	case FIOASYNC:
32341bc9751SMark Murray 	case FIONBIO:
324e7806b4cSMark Murray 		break;
32541bc9751SMark Murray 	default:
326e7806b4cSMark Murray 		error = ENOTTY;
3274d87a031SMark Murray 	}
32810cb2424SMark Murray 
329e7806b4cSMark Murray 	return (error);
33041bc9751SMark Murray }
3314d87a031SMark Murray 
332d1b06863SMark Murray void
333d1b06863SMark Murray random_source_register(struct random_source *rsource)
334d1b06863SMark Murray {
335d1b06863SMark Murray 	struct random_sources *rrs;
336d1b06863SMark Murray 
337d1b06863SMark Murray 	KASSERT(rsource != NULL, ("invalid input to %s", __func__));
338d1b06863SMark Murray 
339d1b06863SMark Murray 	rrs = malloc(sizeof(*rrs), M_ENTROPY, M_WAITOK);
340d1b06863SMark Murray 	rrs->rrs_source = rsource;
341d1b06863SMark Murray 
342095db7e6SConrad Meyer 	random_harvest_register_source(rsource->rs_source);
343095db7e6SConrad Meyer 
344d1b06863SMark Murray 	printf("random: registering fast source %s\n", rsource->rs_ident);
345d1b06863SMark Murray 	LIST_INSERT_HEAD(&source_list, rrs, rrs_entries);
346d1b06863SMark Murray }
347d1b06863SMark Murray 
348d1b06863SMark Murray void
349d1b06863SMark Murray random_source_deregister(struct random_source *rsource)
350d1b06863SMark Murray {
351d1b06863SMark Murray 	struct random_sources *rrs = NULL;
352d1b06863SMark Murray 
353d1b06863SMark Murray 	KASSERT(rsource != NULL, ("invalid input to %s", __func__));
354095db7e6SConrad Meyer 
355095db7e6SConrad Meyer 	random_harvest_deregister_source(rsource->rs_source);
356095db7e6SConrad Meyer 
357d1b06863SMark Murray 	LIST_FOREACH(rrs, &source_list, rrs_entries)
358d1b06863SMark Murray 		if (rrs->rrs_source == rsource) {
359d1b06863SMark Murray 			LIST_REMOVE(rrs, rrs_entries);
360d1b06863SMark Murray 			break;
361d1b06863SMark Murray 		}
362d1b06863SMark Murray 	if (rrs != NULL)
363d1b06863SMark Murray 		free(rrs, M_ENTROPY);
364d1b06863SMark Murray }
365d1b06863SMark Murray 
366d1b06863SMark Murray static int
367d1b06863SMark Murray random_source_handler(SYSCTL_HANDLER_ARGS)
368d1b06863SMark Murray {
369d1b06863SMark Murray 	struct random_sources *rrs;
370d1b06863SMark Murray 	struct sbuf sbuf;
371d1b06863SMark Murray 	int error, count;
372d1b06863SMark Murray 
373d1b06863SMark Murray 	sbuf_new_for_sysctl(&sbuf, NULL, 64, req);
374d1b06863SMark Murray 	count = 0;
375d1b06863SMark Murray 	LIST_FOREACH(rrs, &source_list, rrs_entries) {
376d1b06863SMark Murray 		sbuf_cat(&sbuf, (count++ ? ",'" : "'"));
377d1b06863SMark Murray 		sbuf_cat(&sbuf, rrs->rrs_source->rs_ident);
378d1b06863SMark Murray 		sbuf_cat(&sbuf, "'");
379d1b06863SMark Murray 	}
380d1b06863SMark Murray 	error = sbuf_finish(&sbuf);
381d1b06863SMark Murray 	sbuf_delete(&sbuf);
382d1b06863SMark Murray 	return (error);
383d1b06863SMark Murray }
384d1b06863SMark Murray SYSCTL_PROC(_kern_random, OID_AUTO, random_sources, CTLTYPE_STRING | CTLFLAG_RD | CTLFLAG_MPSAFE,
385d1b06863SMark Murray 	    NULL, 0, random_source_handler, "A",
386d1b06863SMark Murray 	    "List of active fast entropy sources.");
3875711939bSDavid E. O'Brien 
388e1199601SMark Murray /* ARGSUSED */
389a6278a2aSMark Murray static int
39010cb2424SMark Murray randomdev_modevent(module_t mod __unused, int type, void *data __unused)
3914db9ae91SMark Murray {
392e7806b4cSMark Murray 	int error = 0;
3934d87a031SMark Murray 
3944db9ae91SMark Murray 	switch (type) {
3954db9ae91SMark Murray 	case MOD_LOAD:
396d1b06863SMark Murray 		printf("random: entropy device external interface\n");
39710cb2424SMark Murray 		random_dev = make_dev_credf(MAKEDEV_ETERNAL_KLD, &random_cdevsw,
3983aa77530SMark Murray 		    RANDOM_UNIT, NULL, UID_ROOT, GID_WHEEL, 0644, "random");
39910cb2424SMark Murray 		make_dev_alias(random_dev, "urandom"); /* compatibility */
400e7806b4cSMark Murray 		break;
4014db9ae91SMark Murray 	case MOD_UNLOAD:
402c9ec235cSMark Murray 		destroy_dev(random_dev);
403e7806b4cSMark Murray 		break;
4044db9ae91SMark Murray 	case MOD_SHUTDOWN:
405e7806b4cSMark Murray 		break;
4063e019deaSPoul-Henning Kamp 	default:
4073e019deaSPoul-Henning Kamp 		error = EOPNOTSUPP;
4083e019deaSPoul-Henning Kamp 		break;
4094db9ae91SMark Murray 	}
410e7806b4cSMark Murray 	return (error);
4114db9ae91SMark Murray }
4124db9ae91SMark Murray 
413d1b06863SMark Murray static moduledata_t randomdev_mod = {
414d1b06863SMark Murray 	"random_device",
415d1b06863SMark Murray 	randomdev_modevent,
416d1b06863SMark Murray 	0
417d1b06863SMark Murray };
41810cb2424SMark Murray 
419d1b06863SMark Murray DECLARE_MODULE(random_device, randomdev_mod, SI_SUB_DRIVERS, SI_ORDER_FIRST);
420d1b06863SMark Murray MODULE_VERSION(random_device, 1);
421646041a8SMark Murray MODULE_DEPEND(random_device, crypto, 1, 1, 1);
422646041a8SMark Murray MODULE_DEPEND(random_device, random_harvestq, 1, 1, 1);
423