Repository navigation
Commit 650888d
committed
src: seed V8 from the OS CSPRNG instead of OpenSSL's DRBG
InitializeOncePerProcessInternal() calls CSPRNG(nullptr, 0) to confirm
OpenSSL's random source is seeded and installs a V8 entropy source that
goes through CSPRNG() as well. The first RAND_status() of the process
therefore runs before V8 starts, instantiates the DRBG, and with it
constructs the default provider's algorithm and name tables
(ossl_method_construct, ossl_namemap_stored): 3.7% of the samples of
`node -e 0` on Linux x64, all of it before v8Start.
V8 uses the entropy for hash seeds, address space layout randomization
and Math.random(), none of which are cryptographic, so read the OS
CSPRNG directly through uv_random(). AIX is the exception: uv_random()
reads the blocking /dev/random there, so it stays on OpenSSL's DRBG,
which seeds from /dev/urandom.
Keep activating the default provider at startup, which the eager check
did as a side effect and --openssl-legacy-provider depends on. Its
explicit OSSL_PROVIDER_load() disables OpenSSL's provider fallback, so
without a prior activation the default provider never loads. Run the
seeding check itself only when that provider is unavailable or FIPS is
in effect, the cases where an OpenSSL configuration from any source
can leave the process without a DRBG and an early abort beats a hang
at the first crypto call. Every crypto consumer stays on OpenSSL, and
a system without a usable CSPRNG still aborts at startup, now from
uv_random() failing.
Two other behaviors change. A configuration whose [random] section
names a DRBG that cannot be fetched used to abort at startup; it now
starts and the first crypto call fails on the fetch. With --secure-heap
the process DRBGs are instantiated after the secure heap exists, so
they are allocated from it, and a Worker whose per-thread DRBG cannot
be allocated no longer aborts the process from the entropy callback.
Tests cover both, and the default provider staying active under
--openssl-legacy-provider.
Measured on Linux x64 against an unpatched build of the same tree,
both binaries interleaved, min of 300 runs: `node -e 0` 29.18 ->
27.82 ms, nodeStart to v8Start 2.91 -> 2.11 ms. RAND_status and the
provider's table construction leave the startup profile (2.8% of
samples before); the provider activation that remains is 0.05%. The
first crypto.randomBytes() instantiates the DRBG in 0.19 ms. The
`parallel`, `sequential`, `message`, `es-module` and `addons` suites
show no failure the unpatched build does not have.
Refs: 5cc36c39d2
Refs: #44493
Refs: #46237
Signed-off-by: Colin McDonnell <3084745+colinhacks@users.noreply.github.com>1 parent 791e2d2 commit 650888d
5 files changed
Lines changed: 78 additions & 6 deletions
File tree
- src
- test
- addons/openssl-providers
- fixtures/openssl3-conf
- parallel
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
49 | 49 | | |
50 | 50 | | |
51 | 51 | | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
52 | 55 | | |
53 | 56 | | |
54 | 57 | | |
| |||
1259 | 1262 | | |
1260 | 1263 | | |
1261 | 1264 | | |
1262 | | - | |
1263 | | - | |
| 1265 | + | |
| 1266 | + | |
| 1267 | + | |
| 1268 | + | |
| 1269 | + | |
| 1270 | + | |
| 1271 | + | |
| 1272 | + | |
| 1273 | + | |
| 1274 | + | |
| 1275 | + | |
| 1276 | + | |
| 1277 | + | |
| 1278 | + | |
| 1279 | + | |
| 1280 | + | |
1264 | 1281 | | |
| 1282 | + | |
| 1283 | + | |
| 1284 | + | |
| 1285 | + | |
| 1286 | + | |
1265 | 1287 | | |
1266 | | - | |
1267 | | - | |
1268 | | - | |
1269 | | - | |
| 1288 | + | |
| 1289 | + | |
| 1290 | + | |
1270 | 1291 | | |
| 1292 | + | |
| 1293 | + | |
| 1294 | + | |
1271 | 1295 | | |
1272 | 1296 | | |
1273 | 1297 | | |
| |||
Lines changed: 3 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
57 | 57 | | |
58 | 58 | | |
59 | 59 | | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
64 | 75 | | |
65 | 76 | | |
66 | 77 | | |
| |||
70 | 81 | | |
71 | 82 | | |
72 | 83 | | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
73 | 95 | | |
74 | 96 | | |
75 | 97 | | |
| |||
0 commit comments