Skip to content

Commit 21fa45e

Browse files
committedOct 23, 2022
Solaris: consistantly use /dev/random source
On Solaris, we opt to use /dev/random source instead of /dev/urandom due to reasons explained in the comments and [in this Solaris blog post](https://blogs.oracle.com/solaris/post/solaris-new-system-calls-getentropy2-and-getrandom2). However, we haven't been making the same choice when getting randomness via the `getrandom(2)` function, as we just pass `0` for the flags. We [used to](https://github.com/rust-random/rand/pull/730/files#diff-694d4302a3ff2a976f2fbd34bc05ada22ee61a4e21d2d985beab27f7a809268fR151) always set `GRND_RANDOM`, but that was removed in the move from `OsRng` to this crate. For context, rust-random/rand#730, #9, and #51 are the major changes to the Solaris/Illumos implementation over the years. See the solaris documentation for: - [`getrandom(2)`](https://docs.oracle.com/cd/E88353_01/html/E37841/getrandom-2.html) - [`urandom(4)`](https://docs.oracle.com/cd/E88353_01/html/E37851/urandom-4d.html) I also updated the doucmentation to better reflect when [Illumos added the `getrandom(2)` function](https://www.illumos.org/issues/9971#change-23483). Signed-off-by: Joe Richey <joerichey@google.com>
1 parent 2ec38ad commit 21fa45e

File tree

2 files changed

+7
-11
lines changed

2 files changed

+7
-11
lines changed
 

‎Cargo.toml

+1-1
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ compiler_builtins = { version = "0.1", optional = true }
1818
core = { version = "1.0", optional = true, package = "rustc-std-workspace-core" }
1919

2020
[target.'cfg(unix)'.dependencies]
21-
libc = { version = "0.2.120", default-features = false }
21+
libc = { version = "0.2.128", default-features = false }
2222

2323
[target.'cfg(target_os = "wasi")'.dependencies]
2424
wasi = "0.11"

‎src/solaris_illumos.rs

+6-10
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,11 @@
88

99
//! Implementation for the Solaris family
1010
//!
11-
//! Read from `/dev/random`, with chunks of limited size (256 bytes).
1211
//! `/dev/random` uses the Hash_DRBG with SHA512 algorithm from NIST SP 800-90A.
1312
//! `/dev/urandom` uses the FIPS 186-2 algorithm, which is considered less
14-
//! secure. We choose to read from `/dev/random`.
13+
//! secure. We choose to read from `/dev/random` (and use GRND_RANDOM).
1514
//!
16-
//! Since Solaris 11.3 and mid-2015 illumos, the `getrandom` syscall is available.
15+
//! Solaris 11.3 and late-2018 illumos added the getrandom(2) libc function.
1716
//! To make sure we can compile on both Solaris and its derivatives, as well as
1817
//! function, we check for the existence of getrandom(2) in libc by calling
1918
//! libc::dlsym.
@@ -24,21 +23,18 @@ use crate::{
2423
};
2524
use core::mem::{self, MaybeUninit};
2625

27-
#[cfg(target_os = "illumos")]
28-
type GetRandomFn = unsafe extern "C" fn(*mut u8, libc::size_t, libc::c_uint) -> libc::ssize_t;
29-
#[cfg(target_os = "solaris")]
30-
type GetRandomFn = unsafe extern "C" fn(*mut u8, libc::size_t, libc::c_uint) -> libc::c_int;
31-
3226
pub fn getrandom_inner(dest: &mut [MaybeUninit<u8>]) -> Result<(), Error> {
33-
// getrandom(2) was introduced in Solaris 11.3 for Illumos in 2015.
3427
static GETRANDOM: Weak = unsafe { Weak::new("getrandom\0") };
28+
type GetRandomFn = unsafe extern "C" fn(*mut u8, libc::size_t, libc::c_uint) -> libc::ssize_t;
29+
3530
if let Some(fptr) = GETRANDOM.ptr() {
3631
let func: GetRandomFn = unsafe { mem::transmute(fptr) };
3732
// 256 bytes is the lowest common denominator across all the Solaris
3833
// derived platforms for atomically obtaining random data.
3934
for chunk in dest.chunks_mut(256) {
4035
sys_fill_exact(chunk, |buf| unsafe {
41-
func(buf.as_mut_ptr() as *mut u8, buf.len(), 0) as libc::ssize_t
36+
// A cast is needed for the flags as libc uses the wrong type.
37+
func(buf.as_mut_ptr() as *mut u8, buf.len(), libc::GRND_RANDOM as _)
4238
})?
4339
}
4440
Ok(())

0 commit comments

Comments
 (0)