Automatically seeding rand() and mt_rand()

From: Date: Sun, 07 Oct 2001 11:28:57 +0000
Subject: Automatically seeding rand() and mt_rand()
Groups: php.dev 
Request: Send a blank email to php-dev+get-67469@lists.php.net to get a copy of this message
I have posted this before, but I will try again. We have once again seen people do silly stuff like this: srand ((double) microtime() * 1000000); $new_id = md5(rand()); session_id($new_id); It occurs to me that it is useless to have a rand() function in PHP that is not automatically seeded. The rand() function is useless without a fairly unique seed, and it is fairly difficult to get a good seed from within PHP. Then you have to add more PHP code to test whether or not you have seeded in a previous script. If, in ext/standard/rand.c one were to add a global variable: "rand_seed" set to zero. In the function php_srand, keep it updated, and in php_rand check if it is zero, if so call php_srand() with the results from: GENERATE_SEED(); to update the random seed. A great deal of programming atrocities can be avoided, and rand() will, in fact, be more random. This is the patch I want to commit: --- oldrand.c Sun Oct 7 07:12:59 2001 +++ rand.c Sun Oct 7 07:11:58 2001 @@ -38,6 +38,7 @@ #include "basic_functions.h" +long rand_seed = 0; /* SYSTEM RAND FUNCTIONS */ @@ -45,6 +46,7 @@ */ PHPAPI void php_srand(long seed TSRMLS_DC) { + rand_seed = seed; #ifdef ZTS BG(rand_seed) = (unsigned int) seed; #else @@ -328,6 +330,10 @@ if (argc != 0 && zend_parse_parameters(argc TSRMLS_CC, "ll", &min, &max) == FAILURE) return; + if(rand_seed == 0) { + long seed = GENERATE_SEED(); + php_srand(seed TSRMLS_CC); + } number = php_rand(TSRMLS_C); if (argc == 2) {

« previous php.dev (#67469) next »