Skip to content

AIX chroot fix - #2243

Merged
atomicturtle merged 3 commits into
ossec:mainfrom
atomicturtle:fix/aix-agent-chroot-rng
Aug 2, 2026
Merged

atomicturtle merged 3 commits into
ossec:mainfrom
atomicturtle:fix/aix-agent-chroot-rng

Conversation

@atomicturtle

Copy link
Copy Markdown
Member

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aims to fix entropy acquisition failures after chroot (notably on AIX) by moving random-byte generation away from OpenSSL RAND_bytes() and toward OS-native entropy sources that can be safely used across chroot.

Changes:

  • Adds randombytes_try() with OS-specific implementations (Windows CryptoAPI, OpenBSD arc4random_buf, and Unix /dev/urandom//dev/random with a shared FD protected by a mutex and bounded wait).
  • Replaces OpenSSL RAND_bytes() usage in message/token creation, AES IV generation, and agent key generation with randombytes_try().
  • Seeds OpenSSL RNG in srandom_init() prior to chroot (and attempts to keep random device FDs open on newer OpenSSL versions).

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
src/shared/randombytes.c Introduces randombytes_try() and pre-chroot OpenSSL RNG seeding to avoid post-chroot device-path failures.
src/headers/randombytes.h Exposes randombytes_try() API alongside existing randombytes()/srandom_init().
src/os_crypto/shared/msgs.c Switches per-message randomness to randombytes_try() and adds an encryption failure check.
src/os_crypto/aes/aes_op.c Switches AES IV generation to randombytes_try() and fixes failure propagation when IV generation/encrypt fails.
src/addagent/manage_keys.c Switches bulk key generation entropy source to randombytes_try() and returns non-zero on RNG failure.
src/addagent/manage_agents.c Switches agent key generation entropy source to randombytes_try().

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/shared/randombytes.c
Comment on lines +26 to 28
int randombytes_try(void *ptr, size_t length)
{
#ifdef WIN32
Comment thread src/shared/randombytes.c Outdated
Comment on lines +169 to +171
#if OPENSSL_VERSION_NUMBER >= 0x10101000L
RAND_keep_random_devices_open(1);
#endif
WIP

Signed-off-by: Scott R. Shinn <scott@atomicorp.com>
Keep the entropy FD usable after chroot, guard API edge cases, and
avoid fork-time mutex deadlocks / Windows DWORD truncation.

- Guard null/zero length in randombytes_try
- Exclude LibreSSL from RAND_keep_random_devices_open
- Keep entropy FD across transient read failures
- pthread_atfork + O_CLOEXEC for the shared entropy FD
- Reject oversized CryptGenRandom lengths on Windows
@atomicturtle
atomicturtle force-pushed the fix/aix-agent-chroot-rng branch from 177b3b7 to 8efa090 Compare August 2, 2026 21:10
Note PR 2243 in Bug Fixes for keeping OS RNG usable after AIX agent chroot.
@atomicturtle
atomicturtle merged commit 928b24e into ossec:main Aug 2, 2026
5 checks passed
@atomicturtle
atomicturtle deleted the fix/aix-agent-chroot-rng branch August 3, 2026 00:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants