royzah opened a new pull request, #20205:
URL: https://github.com/apache/nuttx/pull/20205

   ## Summary
   
   The i.MX RT117x has a hardware random number generator inside CAAM and 
nothing in NuttX registers it, so `up_randompool_initialize()` is never seeded 
from hardware. There is no CAAM, TRNG or RNG driver anywhere in 
[`arch/arm/src/imxrt`](https://github.com/apache/nuttx/tree/master/arch/arm/src/imxrt),
 and the RT117x headers describe the block only as an [address-map 
comment](https://github.com/apache/nuttx/blob/master/arch/arm/src/imxrt/hardware/rt117x/imxrt117x_memorymap.h#L312).
   
   | File | What it does |
   | --- | --- |
   | `imxrt_caam.c` | job ring zero, and RNG state handle instantiation when 
the boot ROM has not done it |
   | `imxrt_rng.c` | `/dev/random` and `/dev/urandom` on top of it |
   | `hardware/rt117x/imxrt117x_caam.h` | job ring and RNG4 registers |
   | `imxrt_periphclks.h` | the CAAM clock gate, which had no helper |
   
   Instantiation retries with a longer entropy sample until the self test 
passes, which is how NXP's own code finds a value that holds across voltage and 
temperature.
   
   `imxrt_rng.c` is the sibling of the i.MX9 driver in #20191: same health 
checks, same FIPS 140-2 continuous test, and the same refusal to return a short 
read and call it entropy.
   
   Scoped to RT117x, the family that carries CAAM.
   
   ## Impact
   
   New driver, `default n`. Nothing changes for a board that does not select 
`IMXRT_RNG`.
   
   ## Testing
   
   | Build | Result |
   | --- | --- |
   | `imxrt1170-evk:nsh`, `IMXRT_RNG=y` | builds |
   | `imxrt1060-evk:nsh` | builds, so the shared clock-gate header is 
unaffected |
   | `tools/checkpatch.sh -f` on every file | passes |
   
   Draft until it runs on hardware. Boot logs from an RT1176 board to follow.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to