#50437 [Opn->Csd]: Errors in the documentation for mcrypt_create_iv()

From: Date: Tue, 29 Dec 2009 09:43:24 +0000
Subject: #50437 [Opn->Csd]: Errors in the documentation for mcrypt_create_iv()
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-3581@lists.php.net to get a copy of this message
ID: 50437 Updated by: degeberg@php.net Reported By: pierre dot pronchery at duekin dot com -Status: Open +Status: Closed Bug Type: Documentation problem Operating System: All PHP Version: Irrelevant New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2009-12-29 09:43:03] svn@php.net Automatic comment from SVN on behalf of degeberg Revision: http://svn.php.net/viewvc/?view=revision&revision=292735 Log: Fixed #50437. ------------------------------------------------------------------------ [2009-12-10 11:34:06] pierre dot pronchery at duekin dot com Description: ------------ I just noticed two errors in the documentation for mcrypt_create_iv() on PHP.net: 1. "When using MCRYPT_RAND, remember to call srand() before mcrypt_create_iv() to initialize the random number generator; it is not seeded automatically like rand() is." (was supposedly fixed in #28361 but is not/no longer the case) 2. "The source can be MCRYPT_RAND (system random number generator), MCRYPT_DEV_RANDOM (read data from /dev/random) and MCRYPT_DEV_URANDOM (read data from /dev/urandom). MCRYPT_RAND is the only one supported on Windows because Windows (of course) doesn't have /dev/random or /dev/urandom." Reproduce code: --------------- --- From manual page: function.mcrypt-create-iv --- 1. "When using MCRYPT_RAND, remember to call srand() before mcrypt_create_iv() to initialize the random number generator; it is not seeded automatically like rand() is." However, as of PHP 5.3.0, in ext/mcrypt/mcrypt.c: 1362 /* {{{ proto string mcrypt_create_iv(int size, int source) 1363 Create an initialization vector (IV) */ 1364 PHP_FUNCTION(mcrypt_create_iv) 1365 { 1382 if (source == RANDOM || source == URANDOM) { 1424 } else { 1425 n = size; 1426 while (size) { 1427 iv[--size] = (char) (255.0 * php_rand(TSRML S_C) / RAND_MAX); php_rand() is in turn found in ext/standard/rand.c and calls srand() accordingly if necessary. It really isn't necessary to call it explicitly. 2. "The source can be MCRYPT_RAND (system random number generator), MCRYPT_DEV_RANDOM (read data from /dev/random) and MCRYPT_DEV_URANDOM (read data from /dev/urandom). MCRYPT_RAND is the only one supported on Windows because Windows (of course) doesn't have /dev/random or /dev/urandom." This is again wrong, as on Windows: 1382 if (source == RANDOM || source == URANDOM) { 1383 #if PHP_WIN32 1384 /* random/urandom equivalent on Windows */ 1385 HCRYPTPROV hCryptProv; 1386 BYTE *iv_b = (BYTE *) iv; 1387 1388 /* It could be done using LoadLibrary but a s we rely on 2k+ for 5.3, cleaner to use a clear dependency (Advapi 32) and a 1389 standard API call (no f=getAddr..; f();) */ So MCRYPT_DEV_RANDOM and MCRYPT_DEV_URANDOM can indeed be used on Windows as well. Expected result: ---------------- N/A Actual result: -------------- N/A ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=50437&edit=1

« previous php.doc.bugs (#3581) next »