AIX chroot fix - #2243
Merged
Merged
AIX chroot fix#2243
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This PR aims to fix entropy acquisition failures after chroot (notably on AIX) by moving random-byte generation away from OpenSSL RAND_bytes() and toward OS-native entropy sources that can be safely used across chroot.
Changes:
- Adds
randombytes_try()with OS-specific implementations (Windows CryptoAPI, OpenBSDarc4random_buf, and Unix/dev/urandom//dev/randomwith a shared FD protected by a mutex and bounded wait). - Replaces OpenSSL
RAND_bytes()usage in message/token creation, AES IV generation, and agent key generation withrandombytes_try(). - Seeds OpenSSL RNG in
srandom_init()prior tochroot(and attempts to keep random device FDs open on newer OpenSSL versions).
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| src/shared/randombytes.c | Introduces randombytes_try() and pre-chroot OpenSSL RNG seeding to avoid post-chroot device-path failures. |
| src/headers/randombytes.h | Exposes randombytes_try() API alongside existing randombytes()/srandom_init(). |
| src/os_crypto/shared/msgs.c | Switches per-message randomness to randombytes_try() and adds an encryption failure check. |
| src/os_crypto/aes/aes_op.c | Switches AES IV generation to randombytes_try() and fixes failure propagation when IV generation/encrypt fails. |
| src/addagent/manage_keys.c | Switches bulk key generation entropy source to randombytes_try() and returns non-zero on RNG failure. |
| src/addagent/manage_agents.c | Switches agent key generation entropy source to randombytes_try(). |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+26
to
28
| int randombytes_try(void *ptr, size_t length) | ||
| { | ||
| #ifdef WIN32 |
Comment on lines
+169
to
+171
| #if OPENSSL_VERSION_NUMBER >= 0x10101000L | ||
| RAND_keep_random_devices_open(1); | ||
| #endif |
WIP Signed-off-by: Scott R. Shinn <scott@atomicorp.com>
Keep the entropy FD usable after chroot, guard API edge cases, and avoid fork-time mutex deadlocks / Windows DWORD truncation. - Guard null/zero length in randombytes_try - Exclude LibreSSL from RAND_keep_random_devices_open - Keep entropy FD across transient read failures - pthread_atfork + O_CLOEXEC for the shared entropy FD - Reject oversized CryptGenRandom lengths on Windows
atomicturtle
force-pushed
the
fix/aix-agent-chroot-rng
branch
from
August 2, 2026 21:10
177b3b7 to
8efa090
Compare
Note PR 2243 in Bug Fixes for keeping OS RNG usable after AIX agent chroot.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.