Source-Changes-HG archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
[src/trunk]: src/sys/secmodel/securelevel Accept ioctl(RNDADDDATA) estimates ...
details: https://anonhg.NetBSD.org/src/rev/d966684f02c7
branches: trunk
changeset: 1010556:d966684f02c7
user: riastradh <riastradh%NetBSD.org@localhost>
date: Thu May 28 23:17:25 2020 +0000
description:
Accept ioctl(RNDADDDATA) estimates at securelevel 1 (but not 2).
securelevel=1 is supposed to be a reasonable default for normal
computers. This got in the way of ever getting entropy from a seed
on a machine with no HWRNG -- e.g., from another machine, or by
making the executive decision that what has been sampled is good
enough and issuing `head -c 32 < /dev/urandom > /dev/random'.
diffstat:
sys/secmodel/securelevel/secmodel_securelevel.c | 6 +++---
1 files changed, 3 insertions(+), 3 deletions(-)
diffs (27 lines):
diff -r 919d24d510f3 -r d966684f02c7 sys/secmodel/securelevel/secmodel_securelevel.c
--- a/sys/secmodel/securelevel/secmodel_securelevel.c Thu May 28 20:29:21 2020 +0000
+++ b/sys/secmodel/securelevel/secmodel_securelevel.c Thu May 28 23:17:25 2020 +0000
@@ -1,4 +1,4 @@
-/* $NetBSD: secmodel_securelevel.c,v 1.35 2020/05/11 19:36:39 alnsn Exp $ */
+/* $NetBSD: secmodel_securelevel.c,v 1.36 2020/05/28 23:17:25 riastradh Exp $ */
/*-
* Copyright (c) 2006 Elad Efrat <elad%NetBSD.org@localhost>
* All rights reserved.
@@ -35,7 +35,7 @@
*/
#include <sys/cdefs.h>
-__KERNEL_RCSID(0, "$NetBSD: secmodel_securelevel.c,v 1.35 2020/05/11 19:36:39 alnsn Exp $");
+__KERNEL_RCSID(0, "$NetBSD: secmodel_securelevel.c,v 1.36 2020/05/28 23:17:25 riastradh Exp $");
#ifdef _KERNEL_OPT
#include "opt_insecure.h"
@@ -593,7 +593,7 @@
break;
case KAUTH_DEVICE_RND_ADDDATA_ESTIMATE:
- if (securelevel > 0)
+ if (securelevel > 1)
result = KAUTH_RESULT_DENY;
break;
Home |
Main Index |
Thread Index |
Old Index