#50437 [Opn->Csd]: Errors in the documentation for mcrypt_create_iv()
| From: | degeberg@php.net | Date: | Tue, 29 Dec 2009 09:43:24 +0000 |
| Subject: | #50437 [Opn->Csd]: Errors in the documentation for mcrypt_create_iv() | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-3581@lists.php.net to get a copy of this message | ||
ID: 50437
Updated by: degeberg@php.net
Reported By: pierre dot pronchery at duekin dot com
-Status: Open
+Status: Closed
Bug Type: Documentation problem
Operating System: All
PHP Version: Irrelevant
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
Previous Comments:
------------------------------------------------------------------------
[2009-12-29 09:43:03] svn@php.net
Automatic comment from SVN on behalf of degeberg
Revision: http://svn.php.net/viewvc/?view=revision&revision=292735
Log: Fixed #50437.
------------------------------------------------------------------------
[2009-12-10 11:34:06] pierre dot pronchery at duekin dot com
Description:
------------
I just noticed two errors in the documentation for mcrypt_create_iv()
on PHP.net:
1. "When using MCRYPT_RAND, remember to call srand() before
mcrypt_create_iv() to initialize the random number generator; it is not
seeded automatically like rand() is."
(was supposedly fixed in #28361 but is not/no longer the case)
2. "The source can be MCRYPT_RAND (system random number generator),
MCRYPT_DEV_RANDOM (read data from /dev/random) and MCRYPT_DEV_URANDOM
(read data from /dev/urandom). MCRYPT_RAND is the only one supported on
Windows because Windows (of course) doesn't have /dev/random or
/dev/urandom."
Reproduce code:
---------------
---
From manual page: function.mcrypt-create-iv
---
1. "When using MCRYPT_RAND, remember to call srand() before
mcrypt_create_iv() to initialize the random number generator; it is not
seeded automatically like rand() is."
However, as of PHP 5.3.0, in ext/mcrypt/mcrypt.c:
1362 /* {{{ proto string mcrypt_create_iv(int size, int source)
1363 Create an initialization vector (IV) */
1364 PHP_FUNCTION(mcrypt_create_iv)
1365 {
1382 if (source == RANDOM || source == URANDOM) {
1424 } else {
1425 n = size;
1426 while (size) {
1427 iv[--size] = (char) (255.0 *
php_rand(TSRML
S_C) / RAND_MAX);
php_rand() is in turn found in ext/standard/rand.c and calls srand()
accordingly if necessary. It really isn't necessary to call it
explicitly.
2. "The source can be MCRYPT_RAND (system random number generator),
MCRYPT_DEV_RANDOM (read data from /dev/random) and MCRYPT_DEV_URANDOM
(read data from /dev/urandom). MCRYPT_RAND is the only one supported on
Windows because Windows (of course) doesn't have /dev/random or
/dev/urandom."
This is again wrong, as on Windows:
1382 if (source == RANDOM || source == URANDOM) {
1383 #if PHP_WIN32
1384 /* random/urandom equivalent on Windows
*/
1385 HCRYPTPROV hCryptProv;
1386 BYTE *iv_b = (BYTE *) iv;
1387
1388 /* It could be done using LoadLibrary but
a
s we rely on 2k+ for 5.3, cleaner to use a clear dependency
(Advapi
32) and a
1389 standard API call (no
f=getAddr..;
f();) */
So MCRYPT_DEV_RANDOM and MCRYPT_DEV_URANDOM can indeed be used on
Windows as well.
Expected result:
----------------
N/A
Actual result:
--------------
N/A
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=50437&edit=1