#47378 [Opn]: Potential for total failure of uniqid() should be documented
| From: | preinheimer@php.net | Date: | Tue, 17 Feb 2009 21:08:13 +0000 |
| Subject: | #47378 [Opn]: Potential for total failure of uniqid() should be documented | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-1894@lists.php.net to get a copy of this message | ||
ID: 47378
Updated by: preinheimer@php.net
Reported By: tstarling at wikimedia dot org
Status: Open
Bug Type: Documentation problem
Operating System: Cygwin
PHP Version: Irrelevant
Assigned To: preinheimer
New Comment:
Hi,
Just to give you an update I am working on replicating the situation in
a Cygwin environment (somewhere into the third hour of waiting for this
to all build inside a Cygwin instance, within windows, running in a VM).
I'd like to see this actually happen on the off chance there's another
code branch elsewhere coming into play.
I'll also be taking this opportunity to update a few of the other notes
on the Uniqid page, thank you for bringing this to our attention.
paul
Previous Comments:
------------------------------------------------------------------------
[2009-02-13 03:58:34] tstarling at wikimedia dot org
Description:
------------
The source code indicates that uniqid() may completely fail on Cygwin
and return false:
#if HAVE_USLEEP && !defined(PHP_WIN32)
if (!more_entropy) {
#if defined(__CYGWIN__)
php_error_docref(NULL TSRMLS_CC, E_WARNING, "You must use 'more
entropy' under CYGWIN");
RETURN_FALSE;
#else
usleep(1);
#endif
}
#endif
This needs to be documented so that unsuspecting web apps don't become
insecure when run on this platform, e.g. giving everyone the same
default password.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=47378&edit=1