summaryrefslogtreecommitdiff
path: root/arch/x86/kernel/cpu/rdrand.c
blob: c4be62058dd96053bc0f3a2bc4588135f7010a6f (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
// SPDX-License-Identifier: GPL-2.0-only
/*
 * This file is part of the Linux kernel.
 *
 * Copyright (c) 2011, Intel Corporation
 * Authors: Fenghua Yu <fenghua.yu@intel.com>,
 *          H. Peter Anvin <hpa@linux.intel.com>
 */

#include <asm/processor.h>
#include <asm/archrandom.h>
#include <asm/sections.h>

static int __init x86_rdrand_setup(char *s)
{
	setup_clear_cpu_cap(X86_FEATURE_RDRAND);
	setup_clear_cpu_cap(X86_FEATURE_RDSEED);
	return 1;
}
__setup("nordrand", x86_rdrand_setup);

/*
 * RDRAND has Built-In-Self-Test (BIST) that runs on every invocation.
 * Run the instruction a few times as a sanity check.
 * If it fails, it is simple to disable RDRAND here.
 */
#define SANITY_CHECK_LOOPS 8

#ifdef CONFIG_ARCH_RANDOM
void x86_init_rdrand(struct cpuinfo_x86 *c)
{
	unsigned int changed = 0;
	unsigned long tmp, prev;
	int i;

	if (!cpu_has(c, X86_FEATURE_RDRAND))
		return;

	for (i = 0; i < SANITY_CHECK_LOOPS; i++) {
		if (!rdrand_long(&tmp)) {
			clear_cpu_cap(c, X86_FEATURE_RDRAND);
			pr_warn_once("rdrand: disabled\n");
			return;
		}
	}

	/*
	 * Stupid sanity-check whether RDRAND does *actually* generate
	 * some at least random-looking data.
	 */
	prev = tmp;
	for (i = 0; i < SANITY_CHECK_LOOPS; i++) {
		if (rdrand_long(&tmp)) {
			if (prev != tmp)
				changed++;

			prev = tmp;
		}
	}

	if (WARN_ON_ONCE(!changed))
		pr_emerg(
"RDRAND gives funky smelling output, might consider not using it by booting with \"nordrand\"");

}
#endif