[OpenWrt-Devel] [PATCH] kernel/modules: fix crypto API RNG for >=4.2

Stijn Tintel stijn at linux-ipv6.be
Thu Dec 10 07:23:04 EST 2015

Since kernel 4.2, DRBG is the default crypto API RNG, replacing krng. As
DRBG is not enabled, there is no crypto API RNG available when running
kernel 4.2 or later. Because of this, IPsec SAs fail to install. In
strongSwan, this results in a vague error that is difficult to debug:

received netlink error: No such file or directory (2)

Solve this by adding DRBG to the kmod-crypto-rng package. As enabling
DRBG in the kernel config also enables the Jitterentropy RNG, include it
in kmod-crypto-rng instead of having it in a separate package.

Signed-off-by: Stijn Tintel <stijn at linux-ipv6.be>
 package/kernel/linux/modules/crypto.mk | 25 ++++++++++---------------
 1 file changed, 10 insertions(+), 15 deletions(-)

diff --git a/package/kernel/linux/modules/crypto.mk b/package/kernel/linux/modules/crypto.mk
index 062afe7..fe64db4 100644
--- a/package/kernel/linux/modules/crypto.mk
+++ b/package/kernel/linux/modules/crypto.mk
@@ -100,26 +100,21 @@ $(eval $(call KernelPackage,crypto-wq))
 define KernelPackage/crypto-rng
   TITLE:=CryptoAPI random number generation
-  FILES:=$(LINUX_DIR)/crypto/rng.ko
-ifeq ($(strip $(call CompareKernelPatchVer,$(KERNEL_PATCHVER),lt,4.2.0)),1)
-  FILES+=$(LINUX_DIR)/crypto/krng.ko
-  AUTOLOAD:=$(call AutoLoad,09,rng krng)
+  KCONFIG:= \
+  FILES:= \
+	$(LINUX_DIR)/crypto/drbg.ko at ge4.2 \
+	$(LINUX_DIR)/crypto/jitterentropy_rng.ko at ge4.2 \
+	$(LINUX_DIR)/crypto/krng.ko at lt4.2 \
+	$(LINUX_DIR)/crypto/rng.ko
+  AUTOLOAD:=$(call AutoLoad,09,drbg at ge4.2 jitterentropy_rng at ge4.2 krng at lt4.2 rng)
   $(call AddDepends/crypto)
 $(eval $(call KernelPackage,crypto-rng))
-define KernelPackage/crypto-rng-jitterentropy
-  TITLE:=Jitterentropy Non-Deterministic Random Number Generator
-  FILES:= $(LINUX_DIR)/crypto/jitterentropy_rng.ko
-  AUTOLOAD:=$(call AutoLoad,10,jitterentropy-rng)
-  $(call AddDepends/crypto)
-$(eval $(call KernelPackage,crypto-rng-jitterentropy))
 define KernelPackage/crypto-iv
   TITLE:=CryptoAPI initialization vectors
openwrt-devel mailing list
openwrt-devel at lists.openwrt.org

More information about the openwrt-devel mailing list