Bug #65626 [Fbk->Opn]: uniqid(null, false) should guarantee unique identifier

From: Date: Mon, 10 Feb 2014 14:29:39 +0000
Subject: Bug #65626 [Fbk->Opn]: uniqid(null, false) should guarantee unique identifier
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184239@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65626&edit=1 ID: 65626 User updated by: cmbecker69 at gmx dot de Reported by: cmbecker69 at gmx dot de Summary: uniqid(null, false) should guarantee unique identifier -Status: Feedback +Status: Open Type: Bug Package: Unknown/Other Function Operating System: WIN32 PHP Version: 5.4.19 Block user comment: N Private report: N New Comment: I have tested the build with Yasuo's patch on Windows 7 Home Premium SP 1, and it works fine, i.e. I was not able to produce identical uniqid()s. I couldn't test it on an old XP Home SP 3 machine, though, as the build seems to be a 64bit build. > A timeout is still something delaying the script execution, > even for 1us, that's what a PHP developer can decide for > the concrete script. Yes, of course. However, a portable script would have to add the call to usleep(), even if it's unnecessary for *nix systems and actually causes a delay of 2 us there. And actually, I don't see a real issue with using usleep() in uniqid(), as usleep() is used by PHP's usleep()[1], so there would be issues as well. Shifting the burden of calling usleep() to userland won't solve these issues. Regarding Cygwin: I did some builds of PHP 5.4.? and PHP 5.5.? more than half a year ago. However, not everything was usable (e.g. Opcache had to be disabled; otherwise ./configure failed). And the test suite produced a bunch of failures; I tried to submit the resulting report (nearly 1 MB) to the QA list, but somehow it never made it through. FWIW: I didn't manage to build PHP on Cygwin64. [1] <http://lxr.php.net/xref/PHP_5_5/ext/standard/basic_functions.c#4461> Previous Comments: ------------------------------------------------------------------------ [2014-02-10 10:56:58] ab@php.net @cmbecker69, with reopening it was addressed to Yasuo. Uniqueness of that identifier is applicable in the microseconds range only. That scope is also documented, so the behavior is legit. That's the main idea in the helly's post, i think. And his post relates back to 2006 while the relevant code to 2002. For the reasons not to do it on native windows, see below. @yasuo, I've tested your patch on the native windows builds on different VM, it delivers so far without having to use usleep() in the user space. @cmbecker69, could you please test this build http://windows.php.net/downloads/snaps/ostc/65626/ with Yasuo's patch? Still I wouldn't push for this change, testing in VM is something else as the real hardware. Unfortunately I've VMs only right now. Besides that, working on the microtime() bugs has shown that many different constellations of hardware/platform cause various disservices. So fixing it for several constellations contains a high possibility to break it for others. Also in the light of how win8 works now having much better time accuracy, it's probably not future oriented. A timeout is still something delaying the script execution, even for 1us, that's what a PHP developer can decide for the concrete script. So i really think there are more factors against changing this part, except cygwin maybe. The cygwin part is still to be tested by someone who has the build env. Thanks. ------------------------------------------------------------------------ [2014-02-09 12:16:40] cmbecker69 at gmx dot de helly wrote: | To ensure this we use usleep() internally to either force a | thread (windows) or process (*nix) switch. From what I can tell, usleep() is not called on Windows.[1] ab wrote: | For instance, on win8 a snippet "while(uniqid(null, false) | != uniqid(null, false));" loops forever with 5.4 even if | it doesn't have to. However, the documentation[2] states: | Gets a prefixed unique identifier based on the current time | in microseconds. IMHO, a unique identifier should be unique. I have not changed the status, because I had not re-opened the ticket nor had I reported it as bug, but rather as a feature request. [1] <http://lxr.php.net/xref/PHP_TRUNK/ext/standard/uniqid.c#61> [2] <http://php.net/manual/en/function.uniqid.php> ------------------------------------------------------------------------ [2014-02-09 12:16:39] cmbecker69 at gmx dot de helly wrote: | To ensure this we use usleep() internally to either force a | thread (windows) or process (*nix) switch. From what I can tell, usleep() is not called on Windows.[1] ab wrote: | For instance, on win8 a snippet "while(uniqid(null, false) | != uniqid(null, false));" loops forever with 5.4 even if | it doesn't have to. However, the documentation[2] states: | Gets a prefixed unique identifier based on the current time | in microseconds. IMHO, a unique identifier should be unique. I have not changed the status, because I had not re-opened the ticket nor had I reported it as bug, but rather as a feature request. [1] <http://lxr.php.net/xref/PHP_TRUNK/ext/standard/uniqid.c#61> [2] <http://php.net/manual/en/function.uniqid.php> ------------------------------------------------------------------------ [2014-02-08 22:03:49] ab@php.net Hi, I'm not sure why you reopen this ticket :) If you read the helly's comment in bug #37106, it's pretty matching. uniqid() isn't in any way expected to be predictable on different platforms. Btw. never tried to compile it under cygwin. Also see the history, that part was introduced in 2002. Were cygwin builds ever been seriously supported? So where you see a bug here? Nevertheless, the uniqid function is documented as not being secure. usleep() can be used from the userspace and the value is highly variable depending on the platform and hardware. Thanks. ------------------------------------------------------------------------ [2014-02-08 21:09:12] yohgaki@php.net #if HAVE_USLEEP && !defined(PHP_WIN32) !defined(PHP_WIN32) seems legacy check to me as PHP's usleep() only checks HAVE_USLEEP. #if defined(__CYGWIN__) Why Cygwin requires more entropy? I guess the #if check is for assuring uniqueness of uniqid(). Is this needed still? I think we need Windows experts. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=65626 -- Edit this bug report at https://bugs.php.net/bug.php?id=65626&edit=1

« previous php.bugs (#184239) next »