Skip to content

Back RngLib with the hardware TRNG - #288

Closed
C-Prime90 wants to merge 1 commit into
edk2-porting:masterfrom
C-Prime90:PR-RNG-Hardware-TRNG
Closed

C-Prime90 wants to merge 1 commit into
edk2-porting:masterfrom
C-Prime90:PR-RNG-Hardware-TRNG

Conversation

@C-Prime90

Copy link
Copy Markdown
Contributor

The SoC has a non-secure TRNG at 0xfe378000 that nothing was using. RngLib
resolved to BaseRngLibTimerLib — the performance counter, reporting
gEdkiiRngAlgorithmUnSafe — and that's what TlsDxe, Hash2DxeCrypto and
IScsiDxe link against, so HTTPS boot was seeded from a timer.
EFI_RNG_PROTOCOL was unaffected: RngDxe sorts an unsafe RngLib algorithm to
the end of its list and serves Raw from TF-A's SMCCC TRNG first.

It has to be a RngLib instance, not DxeRngLib — that depexes on
gEfiRngProtocolGuid, which RngDxe both produces and consumes RngLib for, so
RngDxe would wait on a protocol only it can install and never dispatch.

GetRngGuid reports gRk3588RngAlgorithmTrngV1Guid rather than
gEfiRngAlgorithmRaw, which is already taken by the SMCCC TRNG and would
advertise the same algorithm twice. EFI_RNG_PROTOCOL gains a second entry
and this block becomes its default. On fallback the library reports UnSafe
and RngDxe demotes it as before.

The version register is checked before anything else is touched, falling back
to the performance counter if it doesn't answer, so a board where the block
is unreachable behaves as it did before.

Verified on a PowerStation 6 over serial: Rk3588Rng: TRNG v1 ready. under
both RngDxe and TlsDxe, with RngDxe's unsafe-algorithm warning absent.
Enabled by default via RK3588_TRNG_ENABLE.

The SoC has a non-secure TRNG at 0xfe378000 that nothing was using. RngLib
resolved to BaseRngLibTimerLib, which derives numbers from the performance
counter and reports gEdkiiRngAlgorithmUnSafe -- and that is what TlsDxe,
Hash2DxeCrypto and IScsiDxe link against, so HTTPS boot was seeded from a
timer. EFI_RNG_PROTOCOL was unaffected: RngDxe sorts an unsafe RngLib
algorithm to the end of its list and serves Raw from TF-A's SMCCC TRNG
first, so the entropy handed to the OS was already hardware.

Add a RngLib instance for the block. It cannot be DxeRngLib -- that depexes
on gEfiRngProtocolGuid, which RngDxe itself produces while also consuming
RngLib, so RngDxe would wait on a protocol only it can install and never
dispatch.

The block is TRNG v1, matching mainline's rockchip,rk3588-rng -- not the
RK356x RNG, which sits in the crypto v2 unit with an unrelated layout. The
version register is checked before anything else is touched and the library
falls back to the performance counter if it does not answer, so a board
where the block is unreachable behaves as it did before.

GetRngGuid reports gRk3588RngAlgorithmTrngV1Guid, a GUID of its own, rather
than gEfiRngAlgorithmRaw: RngDxe registers each source it can serve
separately, and reusing Raw -- already taken by the SMCCC TRNG -- would
advertise the same algorithm twice. EFI_RNG_PROTOCOL therefore gains a
second entry and this block becomes its default, ahead of the SMCCC TRNG.
On fallback the library reports UnSafe and RngDxe demotes it as before.

Enabled by default for RK3588 via RK3588_TRNG_ENABLE.

Verified on a PowerStation 6 over serial: the probe reports "TRNG v1 ready"
under both RngDxe and TlsDxe, and RngDxe's unsafe-algorithm warning does not
appear, so the block is in use rather than falling back to the timer.
@mariobalanica

Copy link
Copy Markdown
Collaborator

It has to be a RngLib instance, not DxeRngLib — that depexes on
gEfiRngProtocolGuid, which RngDxe both produces and consumes RngLib for, so
RngDxe would wait on a protocol only it can install and never dispatch.

Right, but we don't have to link RngDxe against DxeRngLib. It can remain the BaseRngLibTimerLib instance, and for UEFI_DRIVERs (which TlsDxe & the others are), you can simply add RngLib|MdePkg/Library/DxeRngLib/DxeRngLib.inf to:

[LibraryClasses.common.UEFI_DRIVER]

which overrides the timer-based instance just for that driver type.

So we don't actually need a second driver here.

@mariobalanica

Copy link
Copy Markdown
Collaborator

be4d361

@C-Prime90

Copy link
Copy Markdown
Contributor Author

Obsoleted by be4d361 — that covers the
UEFI_DRIVER consumers, and TF-A's rk3588_trng.c already drives the same
block at 0xfe378000, so a second instance buys nothing. Closing.

@C-Prime90 C-Prime90 closed this Sep 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants