This is an automated email from the ASF dual-hosted git repository.

acassis pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/nuttx.git

commit 40783f8343165557827c752b4617838c50dc4aa8
Author: Royyan Zahir <[email protected]>
AuthorDate: Wed Sep 23 16:43:03 2026 +0400

    Documentation/imx9: describe the ELE random number generator
    
    The i.MX9x platform page carried only a board toctree, so there was nowhere
    describing what the chip supports.
    
    Add a peripheral table and a section on the random number generator: the
    Kconfig chain, which of DEV_RANDOM and DEV_URANDOM come on by themselves,
    and the health checks a block must pass before a read returns it.
    
    Signed-off-by: Royyan Zahir <[email protected]>
---
 Documentation/platforms/arm64/imx9/index.rst | 36 ++++++++++++++++++++++++++++
 1 file changed, 36 insertions(+)

diff --git a/Documentation/platforms/arm64/imx9/index.rst 
b/Documentation/platforms/arm64/imx9/index.rst
index 4b1e5b74120..935542f51d9 100644
--- a/Documentation/platforms/arm64/imx9/index.rst
+++ b/Documentation/platforms/arm64/imx9/index.rst
@@ -2,6 +2,42 @@
 NXP i.MX9
 =========
 
+Peripheral Support
+==================
+
+==========  =======  =====================================================
+Peripheral  Support  Notes
+==========  =======  =====================================================
+ELE         Yes      EdgeLock Enclave, used for entropy and secure boot
+RNG         Yes      ``/dev/random`` and ``/dev/urandom``, backed by the ELE
+==========  =======  =====================================================
+
+RNG
+---
+
+The EdgeLock Enclave contains a true random number generator. 
``CONFIG_IMX9_RNG``
+registers it as ``/dev/random`` and ``/dev/urandom``, which is what seeds the
+kernel entropy pool from hardware. Without it ``up_randompool_initialize()``
+has no hardware source.
+
+``CONFIG_IMX9_RNG`` selects ``CONFIG_IMX9_ELE`` and ``CONFIG_ARCH_HAVE_RNG``.
+``CONFIG_DEV_RANDOM`` then defaults on; ``CONFIG_DEV_URANDOM`` does not and 
must
+be set explicitly, after which ``CONFIG_DEV_URANDOM_ARCH`` selects the hardware
+backend rather than the software PRNG.
+
+A read is served in blocks, looping until the request is satisfied. Every block
+is checked before it is returned, and a failed check is an error rather than a
+short read: the buffer must have been written by the ELE, must not be all
+zeros, and must differ from the previous block, which is the FIPS 140-2
+continuous test.
+
+.. code-block:: console
+
+   nsh> hexdump /dev/random -c 32
+   /dev/random at 00000000:
+   0000: 7c 9a f9 b0 fb 89 be 9d 23 bf 17 28 88 43 67 10
+   0010: c5 79 10 9e d7 be ca 42 2f 51 00 bd bc ce 77 54
+
 Supported Boards
 ================
 

Reply via email to