| Josh Gao | a170d9b | 2016-11-10 16:08:29 -0800 | [diff] [blame] | 1 | /* | 
|  | 2 | * Copyright (C) 2016 The Android Open Source Project | 
|  | 3 | * All rights reserved. | 
|  | 4 | * | 
|  | 5 | * Redistribution and use in source and binary forms, with or without | 
|  | 6 | * modification, are permitted provided that the following conditions | 
|  | 7 | * are met: | 
|  | 8 | *  * Redistributions of source code must retain the above copyright | 
|  | 9 | *    notice, this list of conditions and the following disclaimer. | 
|  | 10 | *  * Redistributions in binary form must reproduce the above copyright | 
|  | 11 | *    notice, this list of conditions and the following disclaimer in | 
|  | 12 | *    the documentation and/or other materials provided with the | 
|  | 13 | *    distribution. | 
|  | 14 | * | 
|  | 15 | * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS | 
|  | 16 | * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT | 
|  | 17 | * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS | 
|  | 18 | * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE | 
|  | 19 | * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, | 
|  | 20 | * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, | 
|  | 21 | * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS | 
|  | 22 | * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED | 
|  | 23 | * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, | 
|  | 24 | * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT | 
|  | 25 | * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF | 
|  | 26 | * SUCH DAMAGE. | 
|  | 27 | */ | 
|  | 28 |  | 
|  | 29 | #include "private/bionic_arc4random.h" | 
|  | 30 |  | 
| Josh Gao | a170d9b | 2016-11-10 16:08:29 -0800 | [diff] [blame] | 31 | #include <stdlib.h> | 
| Dan Albert | 1c78cb0 | 2017-10-11 11:25:25 -0700 | [diff] [blame] | 32 | #include <string.h> | 
| Josh Gao | a170d9b | 2016-11-10 16:08:29 -0800 | [diff] [blame] | 33 | #include <sys/auxv.h> | 
| Josh Gao | a170d9b | 2016-11-10 16:08:29 -0800 | [diff] [blame] | 34 | #include <unistd.h> | 
|  | 35 |  | 
| Christopher Ferris | 7a3681e | 2017-04-24 17:48:32 -0700 | [diff] [blame] | 36 | #include <async_safe/log.h> | 
|  | 37 |  | 
| Josh Gao | a170d9b | 2016-11-10 16:08:29 -0800 | [diff] [blame] | 38 | #include "private/KernelArgumentBlock.h" | 
| Josh Gao | a170d9b | 2016-11-10 16:08:29 -0800 | [diff] [blame] | 39 |  | 
| Josh Gao | 585fc3e | 2016-11-10 16:26:44 -0800 | [diff] [blame] | 40 | void __libc_safe_arc4random_buf(void* buf, size_t n, KernelArgumentBlock& args) { | 
| Elliott Hughes | c11fb66 | 2018-02-05 17:28:51 -0800 | [diff] [blame] | 41 | // Only call arc4random_buf once we have `/dev/urandom` because getentropy(3) | 
|  | 42 | // will fall back to using `/dev/urandom` if getrandom(2) fails, and abort if | 
|  | 43 | // if can't use `/dev/urandom`. | 
|  | 44 | static bool have_urandom = access("/dev/urandom", R_OK) == 0; | 
|  | 45 | if (have_urandom) { | 
| Josh Gao | a170d9b | 2016-11-10 16:08:29 -0800 | [diff] [blame] | 46 | arc4random_buf(buf, n); | 
|  | 47 | return; | 
|  | 48 | } | 
|  | 49 |  | 
| Josh Gao | 585fc3e | 2016-11-10 16:26:44 -0800 | [diff] [blame] | 50 | static size_t at_random_bytes_consumed = 0; | 
| Josh Gao | a170d9b | 2016-11-10 16:08:29 -0800 | [diff] [blame] | 51 | if (at_random_bytes_consumed + n > 16) { | 
| Christopher Ferris | 7a3681e | 2017-04-24 17:48:32 -0700 | [diff] [blame] | 52 | async_safe_fatal("ran out of AT_RANDOM bytes, have %zu, requested %zu", | 
|  | 53 | 16 - at_random_bytes_consumed, n); | 
| Josh Gao | a170d9b | 2016-11-10 16:08:29 -0800 | [diff] [blame] | 54 | } | 
|  | 55 |  | 
|  | 56 | memcpy(buf, reinterpret_cast<char*>(args.getauxval(AT_RANDOM)) + at_random_bytes_consumed, n); | 
|  | 57 | at_random_bytes_consumed += n; | 
|  | 58 | return; | 
|  | 59 | } |