Req #80214 [Opn]: random_bytes(): 0 random bytes should be a valid request
| From: | divinity76 at gmail dot com | Date: | Thu, 15 Oct 2020 09:19:36 +0000 |
| Subject: | Req #80214 [Opn]: random_bytes(): 0 random bytes should be a valid request | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229629@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80214&edit=1
ID: 80214
User updated by: divinity76 at gmail dot com
Reported by: divinity76 at gmail dot com
Summary: random_bytes(): 0 random bytes should be a valid
request
Status: Open
Type: Feature/Change Request
Package: Unknown/Other Function
PHP Version: Next Minor Version
Block user comment: N
Private report: N
New Comment:
let me get this straight guys,
requesting str_repeat("A",0) will give you an empty string, as one would expect (request:
repeat "A" 0 times)
requesting random_bytes(0) will give you an exception... (request: give me 0 random bytes)
and both of these make sense to you? it's ok to request a string to be repeated 0 times, but
it's not ok to ask for 0 random bytes? is that the opinion of you guys? or do you guys consider
str_repeat() broken in this regard?
Previous Comments:
------------------------------------------------------------------------
[2020-10-15 03:32:54] a at b dot c dot de
Scenario: I have a block of bytes that I want to pad to a specific length by appending some
randomness (after embedding the message length) because the length of the message would otherwise be
a potential information leak.
The most straightforward way of doing it would be " . random_bytes(strlen($message) %
BLOCK_SIZE)".
To claim that random_bytes(0) should be special-cased is like claiming if() statements should be
written to protect sort() from an empty array argument.
------------------------------------------------------------------------
[2020-10-10 12:42:03] rtrtrtrtrt at dfdfdfdf dot dfd
seriously what value do you expect by random_bytes(0)
> there are situations where code will dynamically
> determine that they need "0 random bytes"
your example below makes no sense at all - that's what the if-statement is for
> none of those requests are errors
> why is it then an error to ask for 0 random bytes
beause it's not a random string operation but asking fro cryptographic save random and in no
valid real world usecase you really want to operate with an empty string
------------------------------------------------------------------------
[2020-10-10 12:34:50] divinity76 at gmail dot com
Description:
------------
asking random_bytes() for 0 random bytes should be a perfectly valid request (but asking for <0
bytes should not be),
there are situations where code will dynamically determine that they need "0 random
bytes", and then ask random_bytes to get them the number of bytes they determined that they
needed
(as a real-life example of this, check https://3v4l.org/OCBiU ,
and to make that code runnable, go to line 35 and replace
for($i=0;$i<100;++$i){
with for($i=1;$i<100;++$i){ )
but random_bytes will throw an Error when users ask for 0 random bytes. that should be a perfectly
valid request, why is it throwing an Error? when you run str_repeat("",0) or
hex2bin("") or bin2hex("") or base64_decode("") or
base64_encode("") or fwrite($h,"") or
file_put_contents("file",""), none of those requests are errors, why is it then
an error to ask for 0 random bytes?
Test script:
---------------
<?php
for($i=0;$i<9;++$i){
random_bytes($i);
}
echo "success!";
Expected result:
----------------
success!
Actual result:
--------------
Fatal error: Uncaught Error: Length must be greater than 0 in /in/elLeT:4
Stack trace:
#0 /in/elLeT(4): random_bytes(0)
#1 {main}
thrown in /in/elLeT on line 4
Process exited with code 255.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80214&edit=1