php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #50437 Errors in the documentation for mcrypt_create_iv()
Submitted: 2009-12-10 11:34 UTC Modified: 2009-12-29 09:43 UTC
From: pierre dot pronchery at duekin dot com Assigned:
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS: All
Private report: No CVE-ID: None
 [2009-12-10 11:34 UTC] pierre dot pronchery at duekin dot com
Description:
------------
I just noticed two errors in the documentation for mcrypt_create_iv() on PHP.net:

1. "When using MCRYPT_RAND, remember to call srand() before mcrypt_create_iv() to initialize the random number generator; it is not seeded automatically like rand() is."
(was supposedly fixed in #28361 but is not/no longer the case)

2. "The source can be MCRYPT_RAND (system random number generator), MCRYPT_DEV_RANDOM (read data from /dev/random) and MCRYPT_DEV_URANDOM (read data from /dev/urandom). MCRYPT_RAND  is the only one supported on Windows because Windows (of course) doesn't have /dev/random or /dev/urandom."

Reproduce code:
---------------
---
From manual page: function.mcrypt-create-iv
---
1. "When using MCRYPT_RAND, remember to call srand() before mcrypt_create_iv() to initialize the random number generator; it is not seeded automatically like rand() is."

However, as of PHP 5.3.0, in ext/mcrypt/mcrypt.c:
1362 /* {{{ proto string mcrypt_create_iv(int size, int source)
1363    Create an initialization vector (IV) */
1364 PHP_FUNCTION(mcrypt_create_iv)
1365 {
1382         if (source == RANDOM || source == URANDOM) {
1424         } else {
1425                 n = size;
1426                 while (size) {
1427                         iv[--size] = (char) (255.0 * php_rand(TSRML
     S_C) / RAND_MAX);

php_rand() is in turn found in ext/standard/rand.c and calls srand()
accordingly if necessary. It really isn't necessary to call it explicitly.

2. "The source can be MCRYPT_RAND (system random number generator), MCRYPT_DEV_RANDOM (read data from /dev/random) and MCRYPT_DEV_URANDOM (read data from /dev/urandom). MCRYPT_RAND  is the only one supported on Windows because Windows (of course) doesn't have /dev/random or /dev/urandom."

This is again wrong, as on Windows:

1382         if (source == RANDOM || source == URANDOM) {
1383 #if PHP_WIN32
1384                         /* random/urandom equivalent on Windows */
1385                         HCRYPTPROV     hCryptProv;
1386                         BYTE *iv_b = (BYTE *) iv;
1387
1388                         /* It could be done using LoadLibrary but a
     s we rely on 2k+ for 5.3, cleaner to use a clear dependency (Advapi
     32) and a
1389                                 standard API call (no f=getAddr..;
      f();) */

So MCRYPT_DEV_RANDOM and MCRYPT_DEV_URANDOM can indeed be used on Windows as well.

Expected result:
----------------
N/A

Actual result:
--------------
N/A

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2009-12-29 09:43 UTC] svn@php.net
Automatic comment from SVN on behalf of degeberg
Revision: http://svn.php.net/viewvc/?view=revision&revision=292735
Log: Fixed #50437.
 [2009-12-29 09:43 UTC] degeberg@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.


 [2020-02-07 06:09 UTC] phpdocbot@php.net
Automatic comment on behalf of degeberg
Revision: http://git.php.net/?p=doc/en.git;a=commit;h=cc44e2f7bdf8c68988b08f033481f51a0d037467
Log: Fixed #50437.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 13:00:02 2026 UTC