Req #66728 [Csd]: gmp_random is obsolete, switch to gmp_urandomm

From: Date: Sun, 27 Mar 2016 11:36:39 +0000
Subject: Req #66728 [Csd]: gmp_random is obsolete, switch to gmp_urandomm
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200157@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66728&edit=1 ID: 66728 Updated by: nikic@php.net Reported by: asphp at dsgml dot com Summary: gmp_random is obsolete, switch to gmp_urandomm Status: Closed Type: Feature/Change Request Package: GNU MP related PHP Version: Irrelevant Assigned To: nikic Block user comment: N Private report: N New Comment: To clarify, I closed this issue because PHP 5.6 introduced gmp_random_bits() and gmp_random_range(), which supersede the gmp_random() function. Previous Comments: ------------------------------------------------------------------------ [2016-03-27 03:44:51] asphp at dsgml dot com It seems to me that actually gmp_random should be removed. gmp_random_bits() does the 2^n, and gmp_random_range() does a regular range. gmp_random does nothing of any value at all. See also bug: #62375 - gmp_random does actually use that constant. ------------------------------------------------------------------------ [2016-03-27 03:40:49] asphp at dsgml dot com I'm not sure this should be closed. The gmp_random function is very confusing and basically useless. The documentation says: The number will be between zero and the number of bits per limb multiplied by limiter. But the code actually uses mpz_urandomb which states: 0 to 2^n-1, inclusive. And the code does: limiter * GMP_LIMB_BITS So you end up with: 2^(limiter * GMP_LIMB_BITS) which is enormous and worse doesn't match the documentation. The code for the function should stop multiplying by GMP_LIMB_BITS and the documentation should be updated to say it's simply 2^n. ------------------------------------------------------------------------ [2016-03-26 11:23:25] nikic@php.net Closing per previous comment. ------------------------------------------------------------------------ [2015-09-24 20:51:49] rainer dot jung at kippdata dot de IMHO this issue can be closed: starting with PHP 5.6 there is gmp_random_range() which uses mpz_urandomm() and the old gmp_random() uses mpz_urandomb(). Both should be fine. ------------------------------------------------------------------------ [2014-02-17 20:52:46] asphp at dsgml dot com Description: ------------ According to the docs mpz_random (i.e. gmp_random) is obsolete. It's also pretty useless since it returns digits in an undefined range. Instead switch to mpz_urandomm which lets you specify the max directly. PHP could either expose it as is and let people subtract to get the min, or PHP could make it easier and let people specify a min and max. PHP could require that people manually initialize the random state, or just go ahead and do it for them with gmp_randinit_mt. Also once this is a done a PHP warning should be emitted for use of gmp_random. See: https://gmplib.org/manual/Integer-Random-Numbers.html ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66728&edit=1

« previous php.bugs (#200157) next »