Req #80214 [Com]: random_bytes(): 0 random bytes should be a valid request

From: Date: Thu, 15 Oct 2020 03:32:54 +0000
Subject: Req #80214 [Com]: random_bytes(): 0 random bytes should be a valid request
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229628@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80214&edit=1 ID: 80214 Comment by: a at b dot c dot de Reported by: divinity76 at gmail dot com Summary: random_bytes(): 0 random bytes should be a valid request Status: Open Type: Feature/Change Request Package: Unknown/Other Function PHP Version: Next Minor Version Block user comment: N Private report: N New Comment: Scenario: I have a block of bytes that I want to pad to a specific length by appending some randomness (after embedding the message length) because the length of the message would otherwise be a potential information leak. The most straightforward way of doing it would be " . random_bytes(strlen($message) % BLOCK_SIZE)". To claim that random_bytes(0) should be special-cased is like claiming if() statements should be written to protect sort() from an empty array argument. Previous Comments: ------------------------------------------------------------------------ [2020-10-10 12:42:03] rtrtrtrtrt at dfdfdfdf dot dfd seriously what value do you expect by random_bytes(0) > there are situations where code will dynamically > determine that they need "0 random bytes" your example below makes no sense at all - that's what the if-statement is for > none of those requests are errors > why is it then an error to ask for 0 random bytes beause it's not a random string operation but asking fro cryptographic save random and in no valid real world usecase you really want to operate with an empty string ------------------------------------------------------------------------ [2020-10-10 12:34:50] divinity76 at gmail dot com Description: ------------ asking random_bytes() for 0 random bytes should be a perfectly valid request (but asking for <0 bytes should not be), there are situations where code will dynamically determine that they need "0 random bytes", and then ask random_bytes to get them the number of bytes they determined that they needed (as a real-life example of this, check https://3v4l.org/OCBiU , and to make that code runnable, go to line 35 and replace for($i=0;$i<100;++$i){ with for($i=1;$i<100;++$i){ ) but random_bytes will throw an Error when users ask for 0 random bytes. that should be a perfectly valid request, why is it throwing an Error? when you run str_repeat("",0) or hex2bin("") or bin2hex("") or base64_decode("") or base64_encode("") or fwrite($h,"") or file_put_contents("file",""), none of those requests are errors, why is it then an error to ask for 0 random bytes? Test script: --------------- <?php for($i=0;$i<9;++$i){ random_bytes($i); } echo "success!"; Expected result: ---------------- success! Actual result: -------------- Fatal error: Uncaught Error: Length must be greater than 0 in /in/elLeT:4 Stack trace: #0 /in/elLeT(4): random_bytes(0) #1 {main} thrown in /in/elLeT on line 4 Process exited with code 255. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80214&edit=1

« previous php.bugs (#229628) next »