summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorHerbert Xu <herbert@gondor.apana.org.au>2023-03-28 11:35:23 +0800
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2023-05-11 23:00:27 +0900
commit1056b209935d888d1a706eae33e94c02614e8f2e (patch)
tree093f9564aae20d9cabb53041ffef222d98b14dfa
parent9317d6612011bfe1867c9001c36e2078a6211aa9 (diff)
downloadlinux-stable-1056b209935d888d1a706eae33e94c02614e8f2e.tar.gz
linux-stable-1056b209935d888d1a706eae33e94c02614e8f2e.tar.bz2
linux-stable-1056b209935d888d1a706eae33e94c02614e8f2e.zip
crypto: drbg - Only fail when jent is unavailable in FIPS mode
[ Upstream commit 686cd976b6ddedeeb1a1fb09ba53a891d3cc9a03 ] When jent initialisation fails for any reason other than ENOENT, the entire drbg fails to initialise, even when we're not in FIPS mode. This is wrong because we can still use the kernel RNG when we're not in FIPS mode. Change it so that it only fails when we are in FIPS mode. Fixes: 57225e679788 ("crypto: drbg - Use callback API for random readiness") Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au> Reviewed-by: Stephan Mueller <smueller@chronox.de> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au> Signed-off-by: Sasha Levin <sashal@kernel.org>
-rw-r--r--crypto/drbg.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/crypto/drbg.c b/crypto/drbg.c
index c89e26e67740..44b0a7f62402 100644
--- a/crypto/drbg.c
+++ b/crypto/drbg.c
@@ -1520,7 +1520,7 @@ static int drbg_prepare_hrng(struct drbg_state *drbg)
const int err = PTR_ERR(drbg->jent);
drbg->jent = NULL;
- if (fips_enabled || err != -ENOENT)
+ if (fips_enabled)
return err;
pr_info("DRBG: Continuing without Jitter RNG\n");
}