Req #80214 [Opn]: random_bytes(): 0 random bytes should be a valid request

From: Date: Thu, 15 Oct 2020 09:19:36 +0000
Subject: Req #80214 [Opn]: random_bytes(): 0 random bytes should be a valid request
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229629@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80214&edit=1 ID: 80214 User updated by: divinity76 at gmail dot com Reported by: divinity76 at gmail dot com Summary: random_bytes(): 0 random bytes should be a valid request Status: Open Type: Feature/Change Request Package: Unknown/Other Function PHP Version: Next Minor Version Block user comment: N Private report: N New Comment: let me get this straight guys, requesting str_repeat("A",0) will give you an empty string, as one would expect (request: repeat "A" 0 times) requesting random_bytes(0) will give you an exception... (request: give me 0 random bytes) and both of these make sense to you? it's ok to request a string to be repeated 0 times, but it's not ok to ask for 0 random bytes? is that the opinion of you guys? or do you guys consider str_repeat() broken in this regard? Previous Comments: ------------------------------------------------------------------------ [2020-10-15 03:32:54] a at b dot c dot de Scenario: I have a block of bytes that I want to pad to a specific length by appending some randomness (after embedding the message length) because the length of the message would otherwise be a potential information leak. The most straightforward way of doing it would be " . random_bytes(strlen($message) % BLOCK_SIZE)". To claim that random_bytes(0) should be special-cased is like claiming if() statements should be written to protect sort() from an empty array argument. ------------------------------------------------------------------------ [2020-10-10 12:42:03] rtrtrtrtrt at dfdfdfdf dot dfd seriously what value do you expect by random_bytes(0) > there are situations where code will dynamically > determine that they need "0 random bytes" your example below makes no sense at all - that's what the if-statement is for > none of those requests are errors > why is it then an error to ask for 0 random bytes beause it's not a random string operation but asking fro cryptographic save random and in no valid real world usecase you really want to operate with an empty string ------------------------------------------------------------------------ [2020-10-10 12:34:50] divinity76 at gmail dot com Description: ------------ asking random_bytes() for 0 random bytes should be a perfectly valid request (but asking for <0 bytes should not be), there are situations where code will dynamically determine that they need "0 random bytes", and then ask random_bytes to get them the number of bytes they determined that they needed (as a real-life example of this, check https://3v4l.org/OCBiU , and to make that code runnable, go to line 35 and replace for($i=0;$i<100;++$i){ with for($i=1;$i<100;++$i){ ) but random_bytes will throw an Error when users ask for 0 random bytes. that should be a perfectly valid request, why is it throwing an Error? when you run str_repeat("",0) or hex2bin("") or bin2hex("") or base64_decode("") or base64_encode("") or fwrite($h,"") or file_put_contents("file",""), none of those requests are errors, why is it then an error to ask for 0 random bytes? Test script: --------------- <?php for($i=0;$i<9;++$i){ random_bytes($i); } echo "success!"; Expected result: ---------------- success! Actual result: -------------- Fatal error: Uncaught Error: Length must be greater than 0 in /in/elLeT:4 Stack trace: #0 /in/elLeT(4): random_bytes(0) #1 {main} thrown in /in/elLeT on line 4 Process exited with code 255. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80214&edit=1

« previous php.bugs (#229629) next »