Skip to main content

Module entropy

Module entropy 

Source
Expand description

Entropy sources for secret generation.

The point of this module is a rule that is easy to state and easy to get wrong: hardware entropy is mixed in, never consumed raw.

A physical source can be absent, unplugged mid-read, wedged returning constant bytes, counterfeit, or deliberately backdoored. If its output were used directly, anyone who controlled the device would control every key generated on that machine — strictly worse than the OS RNG the feature was meant to improve on. Mixing means the result is at least as good as getrandom no matter what the device does:

output = HKDF-SHA256(ikm = os_bytes ‖ device_bytes, salt = domain, info = purpose)

Three consequences, all deliberate:

  • The default never changes. Source::Os is what every generator uses unless a caller asks for something else.
  • Absence fails closed. A selected device that cannot be read is an error, not a quiet fallback — otherwise the user believes they used the token and did not, which is the one outcome worse than not having the feature.
  • Generation only. The vault salt, the Argon2 salt and backup IVs stay on the OS RNG. A salt that depends on a device turns a lost device into a lost vault, and this module exists to reduce risk, not to add a new way to lose everything.

Structs§

EntropyRng
A RngCore view over a Source, for crates that generate keys themselves.

Enums§

Availability
Result of probing a source without using it.
Source
Where the extra entropy comes from.

Functions§

fill
Fill buf with random bytes from source, mixed with OS entropy.
health_check
Run both health tests, naming which one failed.