#47378 [Opn]: Potential for total failure of uniqid() should be documented

From: Date: Tue, 17 Feb 2009 21:08:13 +0000
Subject: #47378 [Opn]: Potential for total failure of uniqid() should be documented
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-1894@lists.php.net to get a copy of this message
ID: 47378 Updated by: preinheimer@php.net Reported By: tstarling at wikimedia dot org Status: Open Bug Type: Documentation problem Operating System: Cygwin PHP Version: Irrelevant Assigned To: preinheimer New Comment: Hi, Just to give you an update I am working on replicating the situation in a Cygwin environment (somewhere into the third hour of waiting for this to all build inside a Cygwin instance, within windows, running in a VM). I'd like to see this actually happen on the off chance there's another code branch elsewhere coming into play. I'll also be taking this opportunity to update a few of the other notes on the Uniqid page, thank you for bringing this to our attention. paul Previous Comments: ------------------------------------------------------------------------ [2009-02-13 03:58:34] tstarling at wikimedia dot org Description: ------------ The source code indicates that uniqid() may completely fail on Cygwin and return false: #if HAVE_USLEEP && !defined(PHP_WIN32) if (!more_entropy) { #if defined(__CYGWIN__) php_error_docref(NULL TSRMLS_CC, E_WARNING, "You must use 'more entropy' under CYGWIN"); RETURN_FALSE; #else usleep(1); #endif } #endif This needs to be documented so that unsuspecting web apps don't become insecure when run on this platform, e.g. giving everyone the same default password. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=47378&edit=1

« previous php.doc.bugs (#1894) next »