Re: Automatically seeding rand() and mt_rand()
| From: | Sterling Hughes | Date: | Sun, 07 Oct 2001 11:22:34 +0000 |
| Subject: | Re: Automatically seeding rand() and mt_rand() | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-67470@lists.php.net to get a copy of this message | ||
On Sun, 7 Oct 2001 mlwmohawk@mohawksoft.com wrote:
> I have posted this before, but I will try again.
>
> We have once again seen people do silly stuff like this:
>
> srand ((double) microtime() * 1000000);
> $new_id = md5(rand());
> session_id($new_id);
>
> It occurs to me that it is useless to have a rand() function in PHP that
> is not automatically seeded. The rand() function is useless without a
> fairly unique seed, and it is fairly difficult to get a good seed from
> within PHP. Then you have to add more PHP code to test whether or not you
> have seeded in a previous script.
>
> If, in ext/standard/rand.c one were to add a global variable: "rand_seed"
> set to zero. In the function php_srand, keep it updated, and in php_rand
> check if it is zero, if so call php_srand() with the results from:
> GENERATE_SEED(); to update the random seed. A great deal of programming
> atrocities can be avoided, and rand() will, in fact, be more random.
>
> This is the patch I want to commit:
>
Its not ts... I'll commit something similiar in a few minutes (also
taking care of mt_* seeding.
-Sterling
> --- oldrand.c Sun Oct 7 07:12:59 2001
> +++ rand.c Sun Oct 7 07:11:58 2001
> @@ -38,6 +38,7 @@
>
> #include "basic_functions.h"
>
> +long rand_seed = 0;
>
> /* SYSTEM RAND FUNCTIONS */
>
> @@ -45,6 +46,7 @@
> */
> PHPAPI void php_srand(long seed TSRMLS_DC)
> {
> + rand_seed = seed;
> #ifdef ZTS
> BG(rand_seed) = (unsigned int) seed;
> #else
> @@ -328,6 +330,10 @@
> if (argc != 0 && zend_parse_parameters(argc TSRMLS_CC, "ll",
> &min,
> &max) == FAILURE)
> return;
>
> + if(rand_seed == 0) {
> + long seed = GENERATE_SEED();
> + php_srand(seed TSRMLS_CC);
> + }
> number = php_rand(TSRMLS_C);
>
> if (argc == 2) {
>
>
>
>
>