From 66480e8a82976bb565b847ca49340c3b2010a7d2 Mon Sep 17 00:00:00 2001 From: deraadt <> Date: Wed, 6 Nov 2019 16:26:24 +0000 Subject: [PATCH] we have emergency entropy injection code in rc, for if the bootblocks and other methods failed to inject/churn the rng enough. Move it up far earlier. ok naddy sthen kettenis --- src/etc/rc | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/src/etc/rc b/src/etc/rc index 3f5c6e94..4af15cb1 100644 --- a/src/etc/rc +++ b/src/etc/rc @@ -1,4 +1,4 @@ -# $OpenBSD: rc,v 1.539 2019/10/06 16:16:19 sthen Exp $ +# $OpenBSD: rc,v 1.540 2019/11/06 16:26:24 deraadt Exp $ # System startup script run by init on autoboot or after single-user. # Output and error are redirected to console by init, and the console is the @@ -353,6 +353,9 @@ if [[ $1 == shutdown ]]; then exit 0 fi +# If bootblocks failed to give us random, try to cause some churn +(dmesg; sysctl hw.{uuid,serialno,sensors} ) >/dev/random 2>&1 + # Add swap block-devices. swapctl -A -t blk @@ -443,10 +446,6 @@ ifconfig -g carp carpdemote 128 sh /etc/netstart -# Any write triggers a rekey. -dmesg >/dev/random -sysctl hw.{uuid,serialno,sensors} >/dev/random 2>&1 - # Load pf rules and bring up pfsync interface. if [[ $pf != NO ]]; then if [[ -f /etc/pf.conf ]]; then