Re: [RFC][VOTE] RNG fixes

From: Date: Sat, 09 Jul 2016 09:10:11 +0000
Subject: Re: [RFC][VOTE] RNG fixes
References: 1 2 3 4 5 6 7 8 9  Groups: php.internals 
Request: Send a blank email to internals+get-94445@lists.php.net to get a copy of this message
On Jul 9, 2016 4:05 PM, "Leigh" <leight@gmail.com> wrote: > > On Sat, 9 Jul 2016 at 09:49 Pierre Joye <pierre.php@gmail.com> wrote: >> >> >> I am sorry but this PR possibly breaks BC and cases have been clearly explained how and why. Asking to show production code publically is not something that you should request. >> >> I can write a sample app to show you how but given the explanations many gave already.... > > > Just to be clear, you voted no to one BC break, but yes to other BC breaks. I don't know how you pick which ones are acceptable, and which are not. > > Summary BC breaks you voted for: > > * No to changing the output of mt_rand after calling mt_srand with a given seed (when not specifying a min/max) > * Yes to changing the output of mt_rand after calling mt_srand with a given seed (when specifying a min/max) > * Yes to changing the output of rand, shuffle, str_shuffle and array_rand > > Do you see why this looks weird to me? Yes and my mistake, did it too quick. The main issue remains and is not addressed. I may simply move on and all no as I do not see big benefits as of now to change it, especially not as I see many still thinking that change makes php uses more secure ;)

« previous php.internals (#94445) next »