mirror of
https://github.com/apache/nuttx.git
synced 2026-09-10 02:46:33 +00:00
The RP2350 embeds an Arm CryptoCell-style true random number generator: a sampled ring oscillator conditioned by von-Neumann, CRNGT and autocorrelation health tests, presenting 192 bits in the six EHR_DATA words. Add a polling driver that serves those conditioned bits as /dev/random and /dev/urandom. Entropy is drawn rarely (an mbedtls CTR_DRBG seeds once and reseeds occasionally), so a blocking poll is used rather than interrupt plumbing; the hardware health-test failures discard the block and re-arm the source, so only conditioned entropy is returned. A startup self-test gates the source before it is trusted: it draws a sample of the conditioned output and rejects a stuck source (identical consecutive 192-bit blocks), a constant byte, or an absurd run of equal bytes. On failure the source is marked unhealthy and every read returns -EIO, so an entropy consumer fail-stops rather than minting keys on a broken source. (The statistical quality is covered by the hardware VN/CRNGT/autocorr tests; this catches the gross, silent failure modes.) New CONFIG_RP23XX_TRNG selects ARCH_HAVE_RNG, which switches /dev/urandom from the software xorshift PRNG to the hardware source (backing getrandom() and thus any entropy consumer such as mbedtls). Tested on a Raspberry Pi Pico 2 W: /dev/random and /dev/urandom register, the startup self-test passes, a read returns at real ring- oscillator sampling latency (~10 ms / 32 B), two independent samples differ, and mbedtls seeds its CTR_DRBG from /dev/urandom successfully. Assisted-by: Claude (Anthropic Claude Code) Signed-off-by: Ricard Rosson <ricard@groundbits.com> |
||
|---|---|---|
| .. | ||
| arm | ||
| arm64 | ||
| avr | ||
| ceva | ||
| dummy | ||
| hc | ||
| mips | ||
| misoc | ||
| or1k | ||
| renesas | ||
| risc-v | ||
| sim | ||
| sparc | ||
| tricore | ||
| x86 | ||
| x86_64 | ||
| xtensa | ||
| z16 | ||
| z80 | ||
| CMakeLists.txt | ||
| Kconfig | ||