rp23xx: add TRNG driver (hardware /dev/random and /dev/urandom)#19400
rp23xx: add TRNG driver (hardware /dev/random and /dev/urandom)#19400ricardgb wants to merge 1 commit into
Conversation
65925e5 to
27e4ec0
Compare
27e4ec0 to
d2531b2
Compare
|
Thanks for the review @xiaoxiang781216 — all four points addressed in d2531b2:
Also fixed the (As before: this change was made with the help of an AI agent and human-reviewed before pushing.) |
The RP2350 embeds an Arm CryptoCell-style true random number generator: a sampled ring oscillator conditioned by von-Neumann, CRNGT and autocorrelation health tests, presenting 192 bits in the six EHR_DATA words. Add a polling driver that serves those conditioned bits as /dev/random and /dev/urandom. Entropy is drawn rarely (an mbedtls CTR_DRBG seeds once and reseeds occasionally), so a blocking poll is used rather than interrupt plumbing; the hardware health-test failures discard the block and re-arm the source, so only conditioned entropy is returned. A startup self-test gates the source before it is trusted: it draws a sample of the conditioned output and rejects a stuck source (identical consecutive 192-bit blocks), a constant byte, or an absurd run of equal bytes. On failure the source is marked unhealthy and every read returns -EIO, so an entropy consumer fail-stops rather than minting keys on a broken source. (The statistical quality is covered by the hardware VN/CRNGT/autocorr tests; this catches the gross, silent failure modes.) New CONFIG_RP23XX_TRNG selects ARCH_HAVE_RNG, which switches /dev/urandom from the software xorshift PRNG to the hardware source (backing getrandom() and thus any entropy consumer such as mbedtls). Tested on a Raspberry Pi Pico 2 W: /dev/random and /dev/urandom register, the startup self-test passes, a read returns at real ring- oscillator sampling latency (~10 ms / 32 B), two independent samples differ, and mbedtls seeds its CTR_DRBG from /dev/urandom successfully. Assisted-by: Claude (Anthropic Claude Code) Signed-off-by: Ricard Rosson <ricard@groundbits.com>
d2531b2 to
02a9798
Compare
|
@linguini1 commit trailer updated to |
|
@linguini1 on-hardware test logs from a Raspberry Pi Pico 2 W (RP2350), NuttX 13.0.0-RC0, with Both devices register:
Two independent
The boot self-test gates the source (a failed source is marked unhealthy and every read returns Disclosure: these tests were run and captured with the help of an AI agent (Claude Code, Anthropic); results are from real hardware and human-reviewed. |
Summary
The RP2350 (rp23xx) embeds an Arm CryptoCell-style true random number
generator — a sampled ring oscillator conditioned by von-Neumann, CRNGT and
autocorrelation health tests, presenting 192 bits in the six
EHR_DATAwords —but there is no driver for it, so
/dev/urandomon rp23xx is the softwarexorshift PRNG.
This adds
arch/arm/src/rp23xx/rp23xx_rng.c, a polling driver that serves theconditioned hardware bits as
/dev/randomand/dev/urandom. Entropy is drawnrarely (an mbedtls CTR_DRBG seeds once and reseeds occasionally), so a blocking
poll is used rather than interrupt plumbing; health-test failures discard the
block and re-arm the source, so only conditioned entropy is ever returned.
New
CONFIG_RP23XX_TRNGselectsARCH_HAVE_RNG, which switches/dev/urandomfrom the software PRNG to the hardware source (backing
getrandom()and thus anyentropy consumer, e.g. mbedtls).
Impact
CONFIG_RP23XX_TRNG.n).Testing
Tested on a Raspberry Pi Pico 2 W:
/dev/randomand/dev/urandomregister from the TRNG;passes, and mbedtls seeds its CTR_DRBG from
/dev/urandomsuccessfully.Disclosure: this change was prepared by an AI agent (Claude Code) at the
direction of the author, who reviewed and tested it on hardware before
submission.
🤖 Generated with Claude Code