#50437 [NEW]: Errors in the documentation for mcrypt_create_iv()

From: Date: Thu, 10 Dec 2009 11:34:07 +0000
Subject: #50437 [NEW]: Errors in the documentation for mcrypt_create_iv()
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-3436@lists.php.net to get a copy of this message
From: pierre dot pronchery at duekin dot com Operating system: All PHP version: Irrelevant PHP Bug Type: Documentation problem Bug description: Errors in the documentation for mcrypt_create_iv() Description: ------------ I just noticed two errors in the documentation for mcrypt_create_iv() on PHP.net: 1. "When using MCRYPT_RAND, remember to call srand() before mcrypt_create_iv() to initialize the random number generator; it is not seeded automatically like rand() is." (was supposedly fixed in #28361 but is not/no longer the case) 2. "The source can be MCRYPT_RAND (system random number generator), MCRYPT_DEV_RANDOM (read data from /dev/random) and MCRYPT_DEV_URANDOM (read data from /dev/urandom). MCRYPT_RAND is the only one supported on Windows because Windows (of course) doesn't have /dev/random or /dev/urandom." Reproduce code: --------------- --- From manual page: function.mcrypt-create-iv --- 1. "When using MCRYPT_RAND, remember to call srand() before mcrypt_create_iv() to initialize the random number generator; it is not seeded automatically like rand() is." However, as of PHP 5.3.0, in ext/mcrypt/mcrypt.c: 1362 /* {{{ proto string mcrypt_create_iv(int size, int source) 1363 Create an initialization vector (IV) */ 1364 PHP_FUNCTION(mcrypt_create_iv) 1365 { 1382 if (source == RANDOM || source == URANDOM) { 1424 } else { 1425 n = size; 1426 while (size) { 1427 iv[--size] = (char) (255.0 * php_rand(TSRML S_C) / RAND_MAX); php_rand() is in turn found in ext/standard/rand.c and calls srand() accordingly if necessary. It really isn't necessary to call it explicitly. 2. "The source can be MCRYPT_RAND (system random number generator), MCRYPT_DEV_RANDOM (read data from /dev/random) and MCRYPT_DEV_URANDOM (read data from /dev/urandom). MCRYPT_RAND is the only one supported on Windows because Windows (of course) doesn't have /dev/random or /dev/urandom." This is again wrong, as on Windows: 1382 if (source == RANDOM || source == URANDOM) { 1383 #if PHP_WIN32 1384 /* random/urandom equivalent on Windows */ 1385 HCRYPTPROV hCryptProv; 1386 BYTE *iv_b = (BYTE *) iv; 1387 1388 /* It could be done using LoadLibrary but a s we rely on 2k+ for 5.3, cleaner to use a clear dependency (Advapi 32) and a 1389 standard API call (no f=getAddr..; f();) */ So MCRYPT_DEV_RANDOM and MCRYPT_DEV_URANDOM can indeed be used on Windows as well. Expected result: ---------------- N/A Actual result: -------------- N/A -- Edit bug report at http://bugs.php.net/?id=50437&edit=1 -- Try a snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=50437&r=trysnapshot52 Try a snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=50437&r=trysnapshot53 Try a snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=50437&r=trysnapshot60 Fixed in SVN: http://bugs.php.net/fix.php?id=50437&r=fixed Fixed in SVN and need be documented: http://bugs.php.net/fix.php?id=50437&r=needdocs Fixed in release: http://bugs.php.net/fix.php?id=50437&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=50437&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=50437&r=needscript Try newer version: http://bugs.php.net/fix.php?id=50437&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=50437&r=support Expected behavior: http://bugs.php.net/fix.php?id=50437&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=50437&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=50437&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=50437&r=globals PHP 4 support discontinued: http://bugs.php.net/fix.php?id=50437&r=php4 Daylight Savings: http://bugs.php.net/fix.php?id=50437&r=dst IIS Stability: http://bugs.php.net/fix.php?id=50437&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=50437&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=50437&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=50437&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=50437&r=mysqlcfg

« previous php.doc.bugs (#3436) next »