glibc/include
Adhemerval Zanella Netto 6f4e0fcfa2 stdlib: Add arc4random, arc4random_buf, and arc4random_uniform (BZ #4417)
The implementation is based on scalar Chacha20 with per-thread cache.
It uses getrandom or /dev/urandom as fallback to get the initial entropy,
and reseeds the internal state on every 16MB of consumed buffer.

To improve performance and lower memory consumption the per-thread cache
is allocated lazily on first arc4random functions call, and if the
memory allocation fails getentropy or /dev/urandom is used as fallback.
The cache is also cleared on thread exit iff it was initialized (so if
arc4random is not called it is not touched).

Although it is lock-free, arc4random is still not async-signal-safe
(the per thread state is not updated atomically).

The ChaCha20 implementation is based on RFC8439 [1], omitting the final
XOR of the keystream with the plaintext because the plaintext is a
stream of zeros.  This strategy is similar to what OpenBSD arc4random
does.

The arc4random_uniform is based on previous work by Florian Weimer,
where the algorithm is based on Jérémie Lumbroso paper Optimal Discrete
Uniform Generation from Coin Flips, and Applications (2013) [2], who
credits Donald E. Knuth and Andrew C. Yao, The complexity of nonuniform
random number generation (1976), for solving the general case.

The main advantage of this method is the that the unit of randomness is not
the uniform random variable (uint32_t), but a random bit.  It optimizes the
internal buffer sampling by initially consuming a 32-bit random variable
and then sampling byte per byte.  Depending of the upper bound requested,
it might lead to better CPU utilization.

Checked on x86_64-linux-gnu, aarch64-linux, and powerpc64le-linux-gnu.

Co-authored-by: Florian Weimer <fweimer@redhat.com>
Reviewed-by: Yann Droneaud <ydroneaud@opteya.com>

[1] https://datatracker.ietf.org/doc/html/rfc8439
[2] https://arxiv.org/pdf/1304.1916.pdf
2022-07-22 11:58:27 -03:00
..
arpa resolv: Move ns_samename into its own file, and into libc 2021-07-19 07:56:21 +02:00
bits Apply asm redirections in stdio.h before first use [BZ #27087] 2022-07-14 16:01:14 -03:00
gnu Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
net
netinet
programs Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
protocols
rpc
rpcsvc
sys misc: Optimize internal usage of __libc_single_threaded 2022-06-24 17:45:58 -03:00
aio.h Linux: Move aio_suspend, aio_suspend64, __aio_suspend_time64 to libc 2021-06-25 11:55:27 +02:00
aliases.h
alloc_buffer.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
alloca.h
allocate_once.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
ar.h
argp-fmtstream.h
argp.h
argz.h
array_length.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
assert.h
atomic_wide_counter.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
atomic.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
byteswap.h
clone_internal.h Add an internal wrapper for clone, clone2 and clone3 2021-07-14 06:33:58 -07:00
complex.h
cpio.h
crypt.h
ctype.h
des.h
dirent.h Use 64 bit time_t stat internally 2021-06-22 12:09:52 -03:00
dlfcn.h elf: Add _dl_find_object function 2021-12-28 22:52:56 +01:00
dso_handle.h
elf.h
endian.h
envz.h
err.h
errno.h
error.h
execinfo.h
fcntl.h
features-time64.h y2038: Add support for 64-bit time on legacy ABIs 2021-06-15 10:42:11 -03:00
features.h Prepare for glibc 2.35 release. 2022-02-03 00:23:26 -05:00
fenv.h
file_change_detection.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
filename.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
float.h
fmtmsg.h
fnmatch.h
fpu_control.h
fstab.h
fts.h io: Add fts64 with 64-bit time_t support 2021-06-15 10:42:11 -03:00
ftw.h io: Add ftw64 with 64-bit time_t support 2021-06-15 10:42:11 -03:00
gconv.h
getopt_int.h
getopt.h
glob.h Fix extra PLT reference in libc.so due to __glob64_time64 if build with gcc 7.5 on 32bit. 2021-07-01 16:46:59 +02:00
gmp.h
gnu-versions.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
grp-merge.h
grp.h
gshadow.h
iconv.h
idx.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
ifaddrs.h
ifreq.h
ifunc-impl-list.h Add bounds check to __libc_ifunc_impl_list 2022-06-10 17:13:29 +01:00
inline-hashtab.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
intprops.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
inttypes.h
langinfo.h
lastlog.h
libc-diag.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
libc-internal.h elf: Remove __libc_init_secure 2022-04-19 15:52:27 -07:00
libc-pointer-arith.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
libc-symbols.h libc-symbols.h: remove unused macros 2022-07-04 21:15:51 -07:00
libgen.h
libintl.h
limits.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
link.h Add GLIBC_ABI_DT_RELR for DT_RELR support 2022-04-26 10:16:11 -07:00
list_t.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
list.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
locale.h
loop_unroll.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
malloc.h Simplify __malloc_initialized 2021-07-22 18:38:04 +05:30
math-narrow-eval.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
math.h Redirect fma calls to __fma in libm 2021-09-15 22:57:35 +00:00
mcheck.h mcheck: Wean away from malloc hooks [BZ #23489] 2021-07-22 18:38:02 +05:30
memory.h
mntent.h
monetary.h
mqueue.h Linux: Move mq_send, mq_timedsend, __mq_timedsend_time64 to libc 2021-06-25 12:21:12 +02:00
netdb.h nss_files: Move into libc 2021-07-07 18:33:52 +02:00
netgroup.h
nl_types.h
nss_dns.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
nss_files.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
nss.h
nsswitch.h
obstack.h
plural-exp.h
poll.h
printf.h stdio-common: Move union printf_arg int <printf.h> 2022-05-24 08:03:11 +02:00
pthread.h Linux: Move mq_notify from librt to libc 2021-06-25 12:20:47 +02:00
pty.h login: Move libutil into libc 2021-06-30 08:43:37 +02:00
pwd.h
random-bits.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
re_comp.h
regex.h regex: copy back from Gnulib 2021-09-21 08:00:44 -07:00
regexp.h
register-atfork.h Fix deadlock when pthread_atfork handler calls pthread_atfork or dlclose 2022-05-25 11:27:31 +02:00
resolv.h resolv: Move res_queriesmatch to its own file and into libc 2021-07-19 07:56:21 +02:00
rounding-mode.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
rtld-malloc.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
sched.h
scratch_buffer.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
search.h
set-hooks.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
setjmp.h setjmp: Replace jmp_buf-macros.h with jmp_buf-macros.sym 2021-11-22 13:43:22 -03:00
sgtty.h
shadow.h
shlib-compat.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
shm-directory.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
signal.h stdio: Remove the usage of $(fno-unit-at-a-time) for siglist.c 2022-05-13 10:54:41 -03:00
spawn.h
stab.h
stackinfo.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
stap-probe.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
stdc-predef.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
stdint.h
stdio_ext.h
stdio.h stdio: Remove the usage of $(fno-unit-at-a-time) for errlist.c 2022-05-13 10:54:41 -03:00
stdlib.h stdlib: Add arc4random, arc4random_buf, and arc4random_uniform (BZ #4417) 2022-07-22 11:58:27 -03:00
string.h String: Add hidden defs for __memcmpeq() to enable internal usage 2021-10-26 16:51:29 -05:00
strings.h
struct___timeb64.h
struct___timespec64.h
struct___timeval64.h
stubs-prologue.h
syscall.h
sysexits.h
syslog.h
tar.h
termios.h
tgmath.h
time.h clock_settime/clock_gettime: Use __nonnull to avoid null pointer 2022-05-05 17:48:04 +05:30
ttyent.h
uchar.h
ucontext.h
ulimit.h
unistd.h elf: Remove __libc_init_secure 2022-04-19 15:52:27 -07:00
utime.h
utmp.h login: Move libutil into libc 2021-06-30 08:43:37 +02:00
values.h Update copyright dates with scripts/update-copyrights 2022-01-01 11:40:24 -08:00
verify.h
wait.h
wchar.h wcrtomb: Make behavior POSIX compliant 2022-05-13 19:15:46 +05:30
wctype.h
wordexp.h