Re: [kernel-hardening] [PATCH] random: warn when kernel uses unseeded randomness

From: Theodore Ts'o
Date: Wed Jun 21 2017 - 16:39:11 EST


On Wed, Jun 21, 2017 at 04:06:49PM +1000, Michael Ellerman wrote:
> All the distro kernels I'm aware of have DEBUG_KERNEL=y.
>
> Where all includes at least RHEL, SLES, Fedora, Ubuntu & Debian.
>
> So it's still essentially default y.
>
> Emitting *one* warning by default would be reasonable. That gives users
> who are interested something to chase, they can then turn on the option
> to get the full story.
>
> Filling the dmesg buffer with repeated warnings is really not helpful.

I agree completely with all of this. The following patch replaces the
current topmost patch on the random.git tree: