php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #47378 Potential for total failure of uniqid() should be documented
Submitted: 2009-02-13 03:58 UTC Modified: 2009-06-27 10:25 UTC
From: tstarling at wikimedia dot org Assigned: kalle (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS: Cygwin
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: tstarling at wikimedia dot org
New email:
PHP Version: OS:

 

 [2009-02-13 03:58 UTC] tstarling at wikimedia dot org
Description:
------------
The source code indicates that uniqid() may completely fail on Cygwin and return false:

#if HAVE_USLEEP && !defined(PHP_WIN32)
	if (!more_entropy) {
#if defined(__CYGWIN__)
		php_error_docref(NULL TSRMLS_CC, E_WARNING, "You must use 'more entropy' under CYGWIN");
		RETURN_FALSE;
#else
		usleep(1);
#endif
	}
#endif

This needs to be documented so that unsuspecting web apps don't become insecure when run on this platform, e.g. giving everyone the same default password.


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2009-02-17 21:08 UTC] preinheimer@php.net
Hi,

Just to give you an update I am working on replicating the situation in a Cygwin environment (somewhere into the third hour of waiting for this to all build inside a Cygwin instance, within windows, running in a VM). I'd like to see this actually happen on the off chance there's another code branch elsewhere coming into play.

I'll also be taking this opportunity to update a few of the other notes on the Uniqid page, thank you for bringing this to our attention.


paul

 [2009-02-18 17:22 UTC] preinheimer@php.net
Hi,

I expect to be able to push my changes into CVS this afternoon, I will add a note indicating that on Cygwin based systems more_entropy in fact defaults to TRUE (or on), and that it must either default to on, or explicitly be enabled to work properly. 

In order for the problem you've identified to occcur the user must be explicitly declining the more entropy option. Also, they have to be using Cygwin, which was a huge pain in the rear end to get going, but that's neither here nor there.


thanks again for this submission
paul



 [2009-05-22 09:22 UTC] bjori@php.net
Whats the status on this?
 [2009-06-27 10:25 UTC] kalle@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.

Added a note on the uniqid function page saying that the more_entropy parameter must be set to true for it to work under Cygwin.
 [2020-02-07 06:10 UTC] phpdocbot@php.net
Automatic comment on behalf of kalle
Revision: http://git.php.net/?p=doc/en.git;a=commit;h=62b1861791d019bad524cc7855877627ea783599
Log: Fixed #47378 (Potential for total failure of uniqid() should be documented)
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 07:00:02 2026 UTC