Re: Alias openssl_random_pseudo_bytes() to php_random_bytes_throw()
| From: | Kalle Sommer Nielsen | Date: | Fri, 19 Oct 2018 05:29:19 +0000 |
| Subject: | Re: Alias openssl_random_pseudo_bytes() to php_random_bytes_throw() | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-103332@lists.php.net to get a copy of this message | ||
Hi Sammy
Den fre. 19. okt. 2018 kl. 02.38 skrev Sammy Kaye Powers <me@sammyk.me>:
> 4) We get to consolidate our CSPRNG code in one place. This would make
> it nice to be able to upgrade all the CSPRNG code to libsodium's
> CSPRNG if we choose to in the future for example.
I would prefer this, any instead of making it an alias or something,
then just straight down deprecate it instead seems like a more
flawless option to me.
> The change I'm proposing would be to:
>
> 1) Make openssl_random_pseudo_bytes() return bytes from
> php_random_bytes_throw() causing the function to fail closed and never
> returning false.
> 2) Deprecate the usage of the second pass-by-reference parameter and
> remove in PHP 8.0. Until then, it always sets the value to true.
>
> Do you think this kind of change would warrant an RFC?
It would.
--
regards,
Kalle Sommer Nielsen
kalle@php.net