|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2009-12-29 09:43 UTC] svn@php.net
[2009-12-29 09:43 UTC] degeberg@php.net
[2020-02-07 06:09 UTC] phpdocbot@php.net
|
|||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Wed Oct 07 13:00:02 2026 UTC |
Description: ------------ I just noticed two errors in the documentation for mcrypt_create_iv() on PHP.net: 1. "When using MCRYPT_RAND, remember to call srand() before mcrypt_create_iv() to initialize the random number generator; it is not seeded automatically like rand() is." (was supposedly fixed in #28361 but is not/no longer the case) 2. "The source can be MCRYPT_RAND (system random number generator), MCRYPT_DEV_RANDOM (read data from /dev/random) and MCRYPT_DEV_URANDOM (read data from /dev/urandom). MCRYPT_RAND is the only one supported on Windows because Windows (of course) doesn't have /dev/random or /dev/urandom." Reproduce code: --------------- --- From manual page: function.mcrypt-create-iv --- 1. "When using MCRYPT_RAND, remember to call srand() before mcrypt_create_iv() to initialize the random number generator; it is not seeded automatically like rand() is." However, as of PHP 5.3.0, in ext/mcrypt/mcrypt.c: 1362 /* {{{ proto string mcrypt_create_iv(int size, int source) 1363 Create an initialization vector (IV) */ 1364 PHP_FUNCTION(mcrypt_create_iv) 1365 { 1382 if (source == RANDOM || source == URANDOM) { 1424 } else { 1425 n = size; 1426 while (size) { 1427 iv[--size] = (char) (255.0 * php_rand(TSRML S_C) / RAND_MAX); php_rand() is in turn found in ext/standard/rand.c and calls srand() accordingly if necessary. It really isn't necessary to call it explicitly. 2. "The source can be MCRYPT_RAND (system random number generator), MCRYPT_DEV_RANDOM (read data from /dev/random) and MCRYPT_DEV_URANDOM (read data from /dev/urandom). MCRYPT_RAND is the only one supported on Windows because Windows (of course) doesn't have /dev/random or /dev/urandom." This is again wrong, as on Windows: 1382 if (source == RANDOM || source == URANDOM) { 1383 #if PHP_WIN32 1384 /* random/urandom equivalent on Windows */ 1385 HCRYPTPROV hCryptProv; 1386 BYTE *iv_b = (BYTE *) iv; 1387 1388 /* It could be done using LoadLibrary but a s we rely on 2k+ for 5.3, cleaner to use a clear dependency (Advapi 32) and a 1389 standard API call (no f=getAddr..; f();) */ So MCRYPT_DEV_RANDOM and MCRYPT_DEV_URANDOM can indeed be used on Windows as well. Expected result: ---------------- N/A Actual result: -------------- N/A