New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[19.09] Backport rng improvements #73314
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please use git cherry-pick -x ...
to get the commit reference of the original commit into the git history.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What exactly doesn't work with current rngd
on r19.09 that would warrant a backport?
some context: #73007 (comment) |
c094b63
to
d49990f
Compare
I figured the rng bias security improvement, adding jitterentropy, allowing qemu-guest to use rngd, general bug fixes, and no apparent breaking changes were good enough to backport. Feel free to correct me if I am wrong I am unclear with the nix backports policy but I feel it's good enough to warrant a backport of anything as long as it doesn't break anything else. |
... otherwise enabling it causes a merge conflict. Enabling it was necessary to give enough entropy for the sshd daemon in my libvirt/nixops VM to generate keys see NixOS/nixops#1199. (cherry picked from commit c27360a)
Semi-automatic update generated by https://github.com/ryantm/nixpkgs-update tools. This update was made based on information from https://repology.org/metapackage/jitterentropy/versions (cherry picked from commit 0158bc0)
+ run tests + enable jitterentropy by default + add c0bw3b to maintainers (cherry picked from commit 810abeb)
(cherry picked from commit d0aec3b)
d49990f
to
527eebc
Compare
Thank you for your contributions.
|
We have 20.03 now. |
Motivation for this change
Backports many rng improvements in master back down to the stable channel.
Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nix-review --run "nix-review wip"
./result/bin/
)nix path-info -S
before and after)Notify maintainers
cc @c0bw3b @JohnAZoidberg @r-ryantm @teto