Re: Automatically seeding rand() and mt_rand()
| From: | jeroen@php.net | Date: | Sun, 07 Oct 2001 14:02:59 +0000 |
| Subject: | Re: Automatically seeding rand() and mt_rand() | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-67484@lists.php.net to get a copy of this message | ||
<mlwmohawk@mohawksoft.com> wrote in message
news:39791.216.41.12.227.1002455916.squirrel@mail.mohawksoft.com...
> > It is fairly difficult to get at all random numbers within the PC. It
> > is possible to make the rand function automatically to call seed if not
> > done before (the PERL rand does this), however I am not sure that your
> > patch is enough for this. First of all the random number generator
> > shouldn't be seeded globally in multithreaded environment (i. e. your
> > rand_seed variable shouldn't be true global). Otherwise if there are
> > two users calling the same script in different sessions, the first user
> > can easily predict the "random" numbers generated by the second. Such
> > behaviour would be security breach.
> >
> > Better, leave this to the application programmer.
>
> If there is a security reason to reseed, then the application programmer
> can. Automatically seeding if no seed has been submitted does not preclude
> seeding.
There issues were all adressed by my proposal, which seems to not have been
read (again). PLEASE READ IT.
http://www.a-eskwadraat.nl/~jeroen/rand/
Reminder for the advantages: No more mt_rand and rand strangenesses, fully
BC (because existing functions are left alone), and full control for the
application programmer (default is seeding done automagically, if a
programmer want reproducable behaviour it can be done - easily and
logically. And makes implementation of real random number sources possible
within this semantics in PHP, so without adding numerous new functions for
array_rand, array_shuffle, etc etc.
--Jeroen
>
> >
> > Rgds:
> >
> > -- Alex
> >
> >> within PHP. Then you have to add more PHP code to test whether or not
> >> you have seeded in a previous script.
> >>
> >> If, in ext/standard/rand.c one were to add a global variable:
> >> "rand_seed" set to zero. In the function php_srand, keep it updated,
> >> and in php_rand check if it is zero, if so call php_srand() with the
> >> results from: GENERATE_SEED(); to update the random seed. A great deal
> >> of programming atrocities can be avoided, and rand() will, in fact, be
> >> more random.
> >>
> >> This is the patch I want to commit:
> >>
> >> --- oldrand.c Sun Oct 7 07:12:59 2001
> >> +++ rand.c Sun Oct 7 07:11:58 2001
> >> @@ -38,6 +38,7 @@
> >>
> >> #include "basic_functions.h"
> >>
> >> +long rand_seed = 0;
> >>
> >> /* SYSTEM RAND FUNCTIONS */
> >>
> >> @@ -45,6 +46,7 @@
> >> */
> >> PHPAPI void php_srand(long seed TSRMLS_DC)
> >> {
> >> + rand_seed = seed;
> >> #ifdef ZTS
> >> BG(rand_seed) = (unsigned int) seed;
> >> #else
> >> @@ -328,6 +330,10 @@
> >> if (argc != 0 && zend_parse_parameters(argc TSRMLS_CC, "ll",
> >> &min,
> >> &max) == FAILURE)
> >> return;
> >>
> >> + if(rand_seed == 0) {
> >> + long seed = GENERATE_SEED();
> >> + php_srand(seed TSRMLS_CC);
> >> + }
> >> number = php_rand(TSRMLS_C);
> >>
> >> if (argc == 2) {
> >>
> >>
> >>
> >>
> >> --
> >> PHP Development Mailing List
> >> <http://www.php.net/>
> >> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> >> For additional commands, e-mail: php-dev-help@lists.php.net
> >> To contact the list administrators, e-mail:
> >> php-list-admin@lists.php.net
>
>