[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#923675: debian-installer: consider using haveged to gather entropy



Hi Holger,

Holger Levsen <holger@layer-acht.org> (2019-04-20):
> On Sat, Apr 20, 2019 at 02:39:49AM +0200, Cyril Brulebois wrote:
> > I've tweaked it a little so that we log whether haveged is available,
> > and whether it should be started, in case we need to investigate:
> >   https://salsa.debian.org/installer-team/rootskel/blob/master/src/lib/debian-installer-startup.d/S50entropy-source
> 
> nice work!
> 
> does that also mean that haveged get's installed on the final system if
> it's deemed to be useful in d-i or is that still missing?

There's nothing in what I have written (on this bug report or in the
code I've quoted or pointed to) that references /target, no.


TBF I have no idea whether we should do that; the situation is slightly
different as a non-installer/non-live system can carry over entropy from
one boot to the next one, which d-i can't do.

I've focussed on getting entropy issues within d-i fixed, which seemed
urgently needed. I'm fine with people seeking a consensus through
debian-boot@ (and maybe debian-devel@) regarding what should happen in
the installed system.

(I almost mentioned the fix would be trivial as it's about pulling an
extra package, but since we have no rng support in udebs at the moment,
we would have no rng support in d-i thus haveged running, while the
installed system could have rng support… Anyway: deciding what to do is
the important part; implementation should be much more straightforward
than the haveged udeb addition dance I've just orchestrated.)


Cheers,
-- 
Cyril Brulebois (kibi@debian.org)            <https://debamax.com/>
D-I release manager -- Release team member -- Freelance Consultant

Attachment: signature.asc
Description: PGP signature


Reply to: