This is an automated email from the ASF dual-hosted git repository. acassis pushed a commit to branch master in repository https://gitbox.apache.org/repos/asf/nuttx.git
commit 40783f8343165557827c752b4617838c50dc4aa8 Author: Royyan Zahir <[email protected]> AuthorDate: Wed Sep 23 16:43:03 2026 +0400 Documentation/imx9: describe the ELE random number generator The i.MX9x platform page carried only a board toctree, so there was nowhere describing what the chip supports. Add a peripheral table and a section on the random number generator: the Kconfig chain, which of DEV_RANDOM and DEV_URANDOM come on by themselves, and the health checks a block must pass before a read returns it. Signed-off-by: Royyan Zahir <[email protected]> --- Documentation/platforms/arm64/imx9/index.rst | 36 ++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) diff --git a/Documentation/platforms/arm64/imx9/index.rst b/Documentation/platforms/arm64/imx9/index.rst index 4b1e5b74120..935542f51d9 100644 --- a/Documentation/platforms/arm64/imx9/index.rst +++ b/Documentation/platforms/arm64/imx9/index.rst @@ -2,6 +2,42 @@ NXP i.MX9 ========= +Peripheral Support +================== + +========== ======= ===================================================== +Peripheral Support Notes +========== ======= ===================================================== +ELE Yes EdgeLock Enclave, used for entropy and secure boot +RNG Yes ``/dev/random`` and ``/dev/urandom``, backed by the ELE +========== ======= ===================================================== + +RNG +--- + +The EdgeLock Enclave contains a true random number generator. ``CONFIG_IMX9_RNG`` +registers it as ``/dev/random`` and ``/dev/urandom``, which is what seeds the +kernel entropy pool from hardware. Without it ``up_randompool_initialize()`` +has no hardware source. + +``CONFIG_IMX9_RNG`` selects ``CONFIG_IMX9_ELE`` and ``CONFIG_ARCH_HAVE_RNG``. +``CONFIG_DEV_RANDOM`` then defaults on; ``CONFIG_DEV_URANDOM`` does not and must +be set explicitly, after which ``CONFIG_DEV_URANDOM_ARCH`` selects the hardware +backend rather than the software PRNG. + +A read is served in blocks, looping until the request is satisfied. Every block +is checked before it is returned, and a failed check is an error rather than a +short read: the buffer must have been written by the ELE, must not be all +zeros, and must differ from the previous block, which is the FIPS 140-2 +continuous test. + +.. code-block:: console + + nsh> hexdump /dev/random -c 32 + /dev/random at 00000000: + 0000: 7c 9a f9 b0 fb 89 be 9d 23 bf 17 28 88 43 67 10 + 0010: c5 79 10 9e d7 be ca 42 2f 51 00 bd bc ce 77 54 + Supported Boards ================
