Currently we only allow /dev/random and /dev/hwrng as host input
for <rng><backend model='random'/> device. This was added after
various upstream discussions in commit
4932ef45
However this restriction has generated quite a few complaints over
the years, so a new discussion was initiated:
http://www.redhat.com/archives/libvir-list/2016-April/msg00987.html
Several people suggested removing the restriction, and nobody really
spoke up to defend it. So this patch drops the path restriction
entirely
https://bugzilla.redhat.com/show_bug.cgi?id=
1074464
<dd>
<p>
This backend type expects a non-blocking character device as
- input. The only accepted paths are /dev/random and /dev/hwrng.
- The file name is specified as contents of the
+ input. The file name is specified as contents of the
<code>backend</code> element. When no file name is specified
- the hypervisor default is used.
+ the hypervisor default is used. For qemu, the default is
+ /dev/random
</p>
</dd>
<dt><code>egd</code></dt>
<value>random</value>
</attribute>
<choice>
- <value>/dev/random</value>
- <value>/dev/hwrng</value>
+ <ref name='absFilePath'/>
<empty/>
</choice>
</group>
switch ((virDomainRNGBackend) def->backend) {
case VIR_DOMAIN_RNG_BACKEND_RANDOM:
def->source.file = virXPathString("string(./backend)", ctxt);
- if (def->source.file &&
- STRNEQ(def->source.file, "/dev/random") &&
- STRNEQ(def->source.file, "/dev/hwrng")) {
- virReportError(VIR_ERR_XML_ERROR,
- _("file '%s' is not a supported random source"),
- def->source.file);
- goto error;
- }
break;
case VIR_DOMAIN_RNG_BACKEND_EGD:
-boot c \
-usb \
-device virtio-balloon-pci,id=balloon0,bus=pci.0,addr=0x3 \
--object rng-random,id=objrng0,filename=/dev/hwrng \
+-object rng-random,id=objrng0,filename=/dev/urandom \
-device virtio-rng-pci,rng=objrng0,id=rng0,max-bytes=123,period=1234,bus=pci.0,\
addr=0x4
<memballoon model='virtio'/>
<rng model='virtio'>
<rate bytes='123' period='1234'/>
- <backend model='random'>/dev/hwrng</backend>
+ <backend model='random'>/dev/urandom</backend>
</rng>
</devices>
</domain>
</memballoon>
<rng model='virtio'>
<rate bytes='123' period='1234'/>
- <backend model='random'>/dev/hwrng</backend>
+ <backend model='random'>/dev/urandom</backend>
<address type='pci' domain='0x0000' bus='0x00' slot='0x04' function='0x0'/>
</rng>
</devices>