Re: Automatically seeding rand() and mt_rand()

From: Date: Sun, 07 Oct 2001 11:58:36 +0000
Subject: Re: Automatically seeding rand() and mt_rand()
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-67473@lists.php.net to get a copy of this message
> It is fairly difficult to get at all random numbers within the PC. It > is possible to make the rand function automatically to call seed if not > done before (the PERL rand does this), however I am not sure that your > patch is enough for this. First of all the random number generator > shouldn't be seeded globally in multithreaded environment (i. e. your > rand_seed variable shouldn't be true global). Otherwise if there are > two users calling the same script in different sessions, the first user > can easily predict the "random" numbers generated by the second. Such > behaviour would be security breach. > > Better, leave this to the application programmer. If there is a security reason to reseed, then the application programmer can. Automatically seeding if no seed has been submitted does not preclude seeding. > > Rgds: > > -- Alex > >> within PHP. Then you have to add more PHP code to test whether or not >> you have seeded in a previous script. >> >> If, in ext/standard/rand.c one were to add a global variable: >> "rand_seed" set to zero. In the function php_srand, keep it updated, >> and in php_rand check if it is zero, if so call php_srand() with the >> results from: GENERATE_SEED(); to update the random seed. A great deal >> of programming atrocities can be avoided, and rand() will, in fact, be >> more random. >> >> This is the patch I want to commit: >> >> --- oldrand.c Sun Oct 7 07:12:59 2001 >> +++ rand.c Sun Oct 7 07:11:58 2001 >> @@ -38,6 +38,7 @@ >> >> #include "basic_functions.h" >> >> +long rand_seed = 0; >> >> /* SYSTEM RAND FUNCTIONS */ >> >> @@ -45,6 +46,7 @@ >> */ >> PHPAPI void php_srand(long seed TSRMLS_DC) >> { >> + rand_seed = seed; >> #ifdef ZTS >> BG(rand_seed) = (unsigned int) seed; >> #else >> @@ -328,6 +330,10 @@ >> if (argc != 0 && zend_parse_parameters(argc TSRMLS_CC, "ll", >> &min, >> &max) == FAILURE) >> return; >> >> + if(rand_seed == 0) { >> + long seed = GENERATE_SEED(); >> + php_srand(seed TSRMLS_CC); >> + } >> number = php_rand(TSRMLS_C); >> >> if (argc == 2) { >> >> >> >> >> -- >> PHP Development Mailing List <http://www.php.net/> >> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net >> For additional commands, e-mail: php-dev-help@lists.php.net >> To contact the list administrators, e-mail: >> php-list-admin@lists.php.net

« previous php.dev (#67473) next »