Conversation

Particularly exciting to me is the work on allowing nearly all platforms to pass RNG seeds via a boot-time protocol. The hope is that if the hypervisor, kexec, firmware, or traditional bootloader is in a good position to provide an RNG seed, it can do so across platforms. 2/7
Image
1
5
But what I'm hoping is that various bootloaders and architecture firmwares start looking into supporting this using whatever capabilities are available. Other operating systems, such as the BSDs, have managed seed files in their bootloaders with success for a very long time. 6/7
1
6
Now for Linux, the kernel-side pieces are there, and we now just have to fill in the bootloader and firmware side. That's a separate case-by-case puzzle, and as always, there's no doubt work to be done, but the plumbing is starting to be viable. 7/7
1
4
Replying to
Not a bad idea. The pstore-efi case isn't so useful, as EFI already can supply a seed (via EFI_RNG_PROTOCOL). But pstore has a few backends (-blk, -mtd, -ram). Maybe that's the right abstraction for this -- persistent storage w/o a real filesystem. 1/3
1
1
Show replies