From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S934694AbbI2MGV (ORCPT ); Tue, 29 Sep 2015 08:06:21 -0400 Received: from mail-io0-f179.google.com ([209.85.223.179]:35996 "EHLO mail-io0-f179.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752735AbbI2MGO (ORCPT ); Tue, 29 Sep 2015 08:06:14 -0400 Subject: Re: [PATCH 1/3] Make /dev/urandom scalable To: "Theodore Ts'o" , Jeff Epler , Andi Kleen , linux-kernel@vger.kernel.org, kirill.shutemov@linux.intel.com, herbert@gondor.apana.org.au, Andi Kleen References: <5603004A.20801@gmail.com> <20150923232841.GK1747@two.firstfloor.org> <5603E083.8020004@gmail.com> <20150924131235.GB6841@thunk.org> <56041E2C.2030602@gmail.com> <20150924165204.GA2835@unpythonic.net> <56044ADB.5050102@gmail.com> <20150924201413.GA3989@thunk.org> <560532FC.1070601@gmail.com> <56059B8A.2010402@gmail.com> <20150925202425.GA14209@thunk.org> From: Austin S Hemmelgarn Message-ID: <560A7EB3.6070407@gmail.com> Date: Tue, 29 Sep 2015 08:06:11 -0400 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Thunderbird/38.2.0 MIME-Version: 1.0 In-Reply-To: <20150925202425.GA14209@thunk.org> Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-512; boundary="------------ms050806060805020203020800" X-Antivirus: avast! (VPS 150929-0, 2015-09-29), Outbound message X-Antivirus-Status: Clean Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org This is a cryptographically signed message in MIME format. --------------ms050806060805020203020800 Content-Type: text/plain; charset=windows-1252; format=flowed Content-Transfer-Encoding: quoted-printable On 2015-09-25 16:24, Theodore Ts'o wrote: > On Fri, Sep 25, 2015 at 03:07:54PM -0400, Austin S Hemmelgarn wrote: >> >> Interestingly, based on what dieharder is already saying about perform= ance, >> /dev/urandom is slower than AES_OFB (at least, on this particular syst= em, >> happy to provide hardware specs if someone wants). > > Yeah, not surprised by that. We're currently using a crypto hash > instead of AES, which means we're not doing any kind of hardware > acceleration. > > Crazy applications that want to spend 100% of the CPU generating > random numbers instead of you know, doing _useful_ work > notwithstanding, /dev/urandom never had high performance as one of its > design goals. The assumption was that if you needed that kind of > performance, you would use a user-space cryptographic random number > generator. While I do understand that, it's abysmal performance compared to any of=20 the others I tested. Part of the standard testing in dieharder is=20 reporting how many random numbers it can source from the generator per=20 second (it's some bit-width of integers, I just don't remember which).=20 Here's the actual numbers I got: AES_OFB| 1.11e+07 random-glibc2| 6.11e+07 mt19937| 3.30e+07 /dev/urandom| 6.53e+05 That much difference in speed is kind of interesting, and reinforces my=20 statement that you should just use /dev/urandom for seeding other RNG's, = just for a different reason than my original statement. --------------ms050806060805020203020800 Content-Type: application/pkcs7-signature; name="smime.p7s" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="smime.p7s" Content-Description: S/MIME Cryptographic Signature MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgMFADCABgkqhkiG9w0BBwEAAKCC Brgwgga0MIIEnKADAgECAgMRLfgwDQYJKoZIhvcNAQENBQAweTEQMA4GA1UEChMHUm9vdCBD QTEeMBwGA1UECxMVaHR0cDovL3d3dy5jYWNlcnQub3JnMSIwIAYDVQQDExlDQSBDZXJ0IFNp Z25pbmcgQXV0aG9yaXR5MSEwHwYJKoZIhvcNAQkBFhJzdXBwb3J0QGNhY2VydC5vcmcwHhcN MTUwOTIxMTEzNTEzWhcNMTYwMzE5MTEzNTEzWjBjMRgwFgYDVQQDEw9DQWNlcnQgV29UIFVz ZXIxIzAhBgkqhkiG9w0BCQEWFGFoZmVycm9pbjdAZ21haWwuY29tMSIwIAYJKoZIhvcNAQkB FhNhaGVtbWVsZ0BvaGlvZ3QuY29tMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA nQ/81tq0QBQi5w316VsVNfjg6kVVIMx760TuwA1MUaNQgQ3NyUl+UyFtjhpkNwwChjgAqfGd LIMTHAdObcwGfzO5uI2o1a8MHVQna8FRsU3QGouysIOGQlX8jFYXMKPEdnlt0GoQcd+BtESr pivbGWUEkPs1CwM6WOrs+09bAJP3qzKIr0VxervFrzrC5Dg9Rf18r9WXHElBuWHg4GYHNJ2V Ab8iKc10h44FnqxZK8RDN8ts/xX93i9bIBmHnFfyNRfiOUtNVeynJbf6kVtdHP+CRBkXCNRZ qyQT7gbTGD24P92PS2UTmDfplSBcWcTn65o3xWfesbf02jF6PL3BCrVnDRI4RgYxG3zFBJuG qvMoEODLhHKSXPAyQhwZINigZNdw5G1NqjXqUw+lIqdQvoPijK9J3eijiakh9u2bjWOMaleI SMRR6XsdM2O5qun1dqOrCgRkM0XSNtBQ2JjY7CycIx+qifJWsRaYWZz0aQU4ZrtAI7gVhO9h pyNaAGjvm7PdjEBiXq57e4QcgpwzvNlv8pG1c/hnt0msfDWNJtl3b6elhQ2Pz4w/QnWifZ8E BrFEmjeeJa2dqjE3giPVWrsH+lOvQQONsYJOuVb8b0zao4vrWeGmW2q2e3pdv0Axzm/60cJQ haZUv8+JdX9ZzqxOm5w5eUQSclt84u+D+hsCAwEAAaOCAVkwggFVMAwGA1UdEwEB/wQCMAAw VgYJYIZIAYb4QgENBEkWR1RvIGdldCB5b3VyIG93biBjZXJ0aWZpY2F0ZSBmb3IgRlJFRSBo ZWFkIG92ZXIgdG8gaHR0cDovL3d3dy5DQWNlcnQub3JnMA4GA1UdDwEB/wQEAwIDqDBABgNV HSUEOTA3BggrBgEFBQcDBAYIKwYBBQUHAwIGCisGAQQBgjcKAwQGCisGAQQBgjcKAwMGCWCG SAGG+EIEATAyBggrBgEFBQcBAQQmMCQwIgYIKwYBBQUHMAGGFmh0dHA6Ly9vY3NwLmNhY2Vy dC5vcmcwMQYDVR0fBCowKDAmoCSgIoYgaHR0cDovL2NybC5jYWNlcnQub3JnL3Jldm9rZS5j cmwwNAYDVR0RBC0wK4EUYWhmZXJyb2luN0BnbWFpbC5jb22BE2FoZW1tZWxnQG9oaW9ndC5j b20wDQYJKoZIhvcNAQENBQADggIBADMnxtSLiIunh/TQcjnRdf63yf2D8jMtYUm4yDoCF++J jCXbPQBGrpCEHztlNSGIkF3PH7ohKZvlqF4XePWxpY9dkr/pNyCF1PRkwxUURqvuHXbu8Lwn 8D3U2HeOEU3KmrfEo65DcbanJCMTTW7+mU9lZICPP7ZA9/zB+L0Gm1UNFZ6AU50N/86vjQfY WgkCd6dZD4rQ5y8L+d/lRbJW7ZGEQw1bSFVTRpkxxDTOwXH4/GpQfnfqTAtQuJ1CsKT12e+H NSD/RUWGTr289dA3P4nunBlz7qfvKamxPymHeBEUcuICKkL9/OZrnuYnGROFwcdvfjGE5iLB kjp/ttrY4aaVW5EsLASNgiRmA6mbgEAMlw3RwVx0sVelbiIAJg9Twzk4Ct6U9uBKiJ8S0sS2 8RCSyTmCRhJs0vvva5W9QUFGmp5kyFQEoSfBRJlbZfGX2ehI2Hi3U2/PMUm2ONuQG1E+a0AP u7I0NJc/Xil7rqR0gdbfkbWp0a+8dAvaM6J00aIcNo+HkcQkUgtfrw+C2Oyl3q8IjivGXZqT 5UdGUb2KujLjqjG91Dun3/RJ/qgQlotH7WkVBs7YJVTCxfkdN36rToPcnMYOI30FWa0Q06gn F6gUv9/mo6riv3A5bem/BdbgaJoPnWQD9D8wSyci9G4LKC+HQAMdLmGoeZfpJzKHMYIE0TCC BM0CAQEwgYAweTEQMA4GA1UEChMHUm9vdCBDQTEeMBwGA1UECxMVaHR0cDovL3d3dy5jYWNl cnQub3JnMSIwIAYDVQQDExlDQSBDZXJ0IFNpZ25pbmcgQXV0aG9yaXR5MSEwHwYJKoZIhvcN AQkBFhJzdXBwb3J0QGNhY2VydC5vcmcCAxEt+DANBglghkgBZQMEAgMFAKCCAiEwGAYJKoZI hvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0BCQUxDxcNMTUwOTI5MTIwNjExWjBPBgkq hkiG9w0BCQQxQgRAx++t0IkAO6q4kL538gSs1iu/JLK2ocrmwfXd6phXGmgQTYaGhVgHd/My z6wansYg67aMy+Br0FDCp54Zr55JIzBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGRBgkrBgEEAYI3EAQxgYMwgYAweTEQMA4GA1UE ChMHUm9vdCBDQTEeMBwGA1UECxMVaHR0cDovL3d3dy5jYWNlcnQub3JnMSIwIAYDVQQDExlD QSBDZXJ0IFNpZ25pbmcgQXV0aG9yaXR5MSEwHwYJKoZIhvcNAQkBFhJzdXBwb3J0QGNhY2Vy dC5vcmcCAxEt+DCBkwYLKoZIhvcNAQkQAgsxgYOggYAweTEQMA4GA1UEChMHUm9vdCBDQTEe MBwGA1UECxMVaHR0cDovL3d3dy5jYWNlcnQub3JnMSIwIAYDVQQDExlDQSBDZXJ0IFNpZ25p bmcgQXV0aG9yaXR5MSEwHwYJKoZIhvcNAQkBFhJzdXBwb3J0QGNhY2VydC5vcmcCAxEt+DAN BgkqhkiG9w0BAQEFAASCAgBJXxj/V91ROzVI27wYTsRSVvEAg9pH1OmY0YA4e4pb0lRayWdy KBtjeYV3VosGjyTVe1jqVADNH6ix0OAEvGXfjKXgvEPyTBXuBGY/OonNGTa3DJw80SWlVM6T Gc/aw41ZCaAsruiCD7jlRzalD+pv129HiJEbsa/3BBA8nNaCTb+AnmYNJGURfhqr0TWIH5m/ c4ztEh7cEWNh99ldFX5l8sLb+YrAu8zqxNE8NCt2UgX1JJS690o8aNRwoK2DmdCUAZRiQkl0 6zFKNIj7qh9YMmYC7EtMteaOoSZ9jLpCWQe1nCahLwNbyny78P5ztSEJre1HeGLpJppObl09 ewiFFnMIcU0h6alBoJsbtkWsetR0yBFe+DHYx5VEjXhDsHd4N2Q3L2PaiSin/6EDt4P5GcI3 hIKCdECuSfcDrBmpJcN4QJBX2dOrxTdbsnCEyAPOtMnVS6WcNzeny7a1py+OVFesugoC6IS2 oLgvSMgYUgBrtDnRRHasIyl0G/EBqbgCEL2OPbGZ6nEcWddAP9qprJt9xKMMb9IfC6VDsCWn ewk2+S3Dd+PwAdqZL5yKZBL3c7hV1OXsUFVSQVfp4Y5E+5hl9BUxahknF4/CJBBw8K0fjqvA jmsNjniqUj7RpXzC4tZQEDJTulbWF5kfOUHmsEYwj+u/JBIEvD7jEvFTYgAAAAAAAA== --------------ms050806060805020203020800--