Skip to content

Commit 650888d

Browse files
committed
src: seed V8 from the OS CSPRNG instead of OpenSSL's DRBG
InitializeOncePerProcessInternal() calls CSPRNG(nullptr, 0) to confirm OpenSSL's random source is seeded and installs a V8 entropy source that goes through CSPRNG() as well. The first RAND_status() of the process therefore runs before V8 starts, instantiates the DRBG, and with it constructs the default provider's algorithm and name tables (ossl_method_construct, ossl_namemap_stored): 3.7% of the samples of `node -e 0` on Linux x64, all of it before v8Start. V8 uses the entropy for hash seeds, address space layout randomization and Math.random(), none of which are cryptographic, so read the OS CSPRNG directly through uv_random(). AIX is the exception: uv_random() reads the blocking /dev/random there, so it stays on OpenSSL's DRBG, which seeds from /dev/urandom. Keep activating the default provider at startup, which the eager check did as a side effect and --openssl-legacy-provider depends on. Its explicit OSSL_PROVIDER_load() disables OpenSSL's provider fallback, so without a prior activation the default provider never loads. Run the seeding check itself only when that provider is unavailable or FIPS is in effect, the cases where an OpenSSL configuration from any source can leave the process without a DRBG and an early abort beats a hang at the first crypto call. Every crypto consumer stays on OpenSSL, and a system without a usable CSPRNG still aborts at startup, now from uv_random() failing. Two other behaviors change. A configuration whose [random] section names a DRBG that cannot be fetched used to abort at startup; it now starts and the first crypto call fails on the fetch. With --secure-heap the process DRBGs are instantiated after the secure heap exists, so they are allocated from it, and a Worker whose per-thread DRBG cannot be allocated no longer aborts the process from the entropy callback. Tests cover both, and the default provider staying active under --openssl-legacy-provider. Measured on Linux x64 against an unpatched build of the same tree, both binaries interleaved, min of 300 runs: `node -e 0` 29.18 -> 27.82 ms, nodeStart to v8Start 2.91 -> 2.11 ms. RAND_status and the provider's table construction leave the startup profile (2.8% of samples before); the provider activation that remains is 0.05%. The first crypto.randomBytes() instantiates the DRBG in 0.19 ms. The `parallel`, `sequential`, `message`, `es-module` and `addons` suites show no failure the unpatched build does not have. Refs: 5cc36c39d2 Refs: #44493 Refs: #46237 Signed-off-by: Colin McDonnell <3084745+colinhacks@users.noreply.github.com>
1 parent 791e2d2 commit 650888d

5 files changed

Lines changed: 78 additions & 6 deletions

File tree

‎src/node.cc‎

Lines changed: 30 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,9 @@
4949

5050
#if HAVE_OPENSSL
5151
#include "ncrypto.h"
52+
#if OPENSSL_VERSION_MAJOR >= 3
53+
#include <openssl/provider.h>
54+
#endif
5255
#include "node_crypto.h"
5356
#if OPENSSL_VERSION_MAJOR >= 3 && !defined(CONF_MFLAGS_IGNORE_MISSING_FILE)
5457
// OpenSSL hides this deprecated macro under OPENSSL_NO_DEPRECATED, but the
@@ -1259,15 +1262,36 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
12591262
}
12601263
crypto::InstallFipsIndicatorCallback();
12611264

1262-
// Ensure CSPRNG is properly seeded.
1263-
CHECK(ncrypto::CSPRNG(nullptr, 0));
1265+
// Activating the default provider here keeps --openssl-legacy-provider
1266+
// working. Its explicit load disables OpenSSL's fallback, and the eager
1267+
// CSPRNG check used to activate the provider as a side effect. Only
1268+
// check the seeding when that provider is missing or FIPS is on, so a
1269+
// configuration without a DRBG still aborts at startup instead of
1270+
// hanging at the first crypto call. Otherwise the DRBG is instantiated
1271+
// on first use.
1272+
#if OPENSSL_VERSION_MAJOR >= 3
1273+
const bool check_csprng = ncrypto::isFipsEnabled() ||
1274+
!OSSL_PROVIDER_available(nullptr, "default");
1275+
#else
1276+
const bool check_csprng = true;
1277+
#endif
1278+
if (check_csprng) {
1279+
CHECK(ncrypto::CSPRNG(nullptr, 0));
1280+
}
12641281

1282+
// V8 uses the entropy for hash seeds, ASLR and Math.random(), none of
1283+
// it cryptographic. Going through OpenSSL would instantiate the DRBG
1284+
// and build the default provider's algorithm tables on every startup.
1285+
// V8 falls back to very weak entropy when the source fails, so abort
1286+
// instead.
12651287
V8::SetEntropySource([](unsigned char* buffer, size_t length) {
1266-
// V8 falls back to very weak entropy when this function fails
1267-
// and /dev/urandom isn't available. That wouldn't be so bad if
1268-
// the entropy was only used for Math.random() but it's also used for
1269-
// hash table and address space layout randomization. Better to abort.
1288+
#ifdef _AIX
1289+
// uv_random() reads /dev/random on AIX, which blocks. OpenSSL seeds
1290+
// from /dev/urandom there.
12701291
CHECK(ncrypto::CSPRNG(buffer, length));
1292+
#else
1293+
CHECK_EQ(uv_random(nullptr, nullptr, buffer, length, 0, nullptr), 0);
1294+
#endif
12711295
return true;
12721296
});
12731297
#endif // !defined(OPENSSL_IS_BORINGSSL)

‎test/addons/openssl-providers/test-legacy-provider-option.js‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,3 +22,6 @@ if (getFips()) {
2222
common.skip('this test cannot be run in FIPS mode');
2323
}
2424
providers.testProviderPresent('legacy');
25+
// The explicit legacy load disables OpenSSL's provider fallback, so the
26+
// default provider has to be active before it runs.
27+
providers.testProviderPresent('default');
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
nodejs_conf = nodejs_init
2+
3+
[nodejs_init]
4+
random = random_sect
5+
6+
[random_sect]
7+
random = NO-SUCH-DRBG

‎test/parallel/test-crypto-no-algorithm.js‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -57,3 +57,19 @@ if (isMainThread) {
5757
assert(common.nodeProcessAborted(cp.status, cp.signal),
5858
`process did not abort, code:${cp.status} signal:${cp.signal}`);
5959
}
60+
61+
{
62+
// A configuration whose random section names a DRBG that cannot be
63+
// fetched starts normally; the first crypto call fails, without a hang.
64+
const fixtures = require('../common/fixtures');
65+
const { spawnSync } = require('node:child_process');
66+
const randomConf = fixtures.path('openssl3-conf', 'random_unavailable.cnf');
67+
const cp = spawnSync(process.execPath,
68+
[ `--openssl-config=${randomConf}`, '-e',
69+
'require("node:crypto").randomBytes(8)' ],
70+
{ encoding: 'utf8' });
71+
assert(!common.nodeProcessAborted(cp.status, cp.signal),
72+
`process aborted, code:${cp.status} signal:${cp.signal}`);
73+
assert.strictEqual(cp.status, 1);
74+
assert.match(cp.stderr, /unable to fetch drbg/);
75+
}

‎test/parallel/test-crypto-secure-heap.js‎

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,17 @@ if (process.argv[2] === 'child') {
6161
return;
6262
}
6363

64+
if (process.argv[2] === 'workers') {
65+
// A Worker's crypto calls may run out of secure heap; that surfaces as an
66+
// error in the Worker, never as an abort of the process.
67+
const { Worker } = require('worker_threads');
68+
for (let i = 0; i < 8; i++) {
69+
new Worker('try { require("crypto").randomBytes(4); } catch {}',
70+
{ eval: true });
71+
}
72+
return;
73+
}
74+
6475
const child = fork(
6576
process.argv[1],
6677
['child'],
@@ -70,6 +81,17 @@ child.on('exit', common.mustCall((code) => {
7081
assert.strictEqual(code, 0);
7182
}));
7283

84+
{
85+
const child = fork(
86+
process.argv[1],
87+
['workers'],
88+
{ execArgv: ['--secure-heap=1024', '--secure-heap-min=4'] });
89+
child.on('exit', common.mustCall((code, signal) => {
90+
assert.strictEqual(signal, null);
91+
assert.strictEqual(code, 0);
92+
}));
93+
}
94+
7395
{
7496
const child = fork(fixtures.path('a.js'), {
7597
execArgv: ['--secure-heap=3', '--secure-heap-min=3'],

0 commit comments

Comments
 (0)