@@ -220,7 +220,7 @@ |
||
220 | 220 | ), |
221 | 221 | ), |
222 | 222 | ); |
223 | - */ |
|
223 | + */ |
|
224 | 224 | |
225 | 225 | // Are we using right-to-left orientation? |
226 | 226 | $first = $context['right_to_left'] ? 'last' : 'first'; |
@@ -1,204 +1,204 @@ |
||
1 | 1 | <?php |
2 | 2 | |
3 | 3 | if (!is_callable('random_int')) { |
4 | - /** |
|
5 | - * Random_* Compatibility Library |
|
6 | - * for using the new PHP 7 random_* API in PHP 5 projects |
|
7 | - * |
|
8 | - * The MIT License (MIT) |
|
9 | - * |
|
10 | - * Copyright (c) 2015 - 2018 Paragon Initiative Enterprises |
|
11 | - * |
|
12 | - * Permission is hereby granted, free of charge, to any person obtaining a copy |
|
13 | - * of this software and associated documentation files (the "Software"), to deal |
|
14 | - * in the Software without restriction, including without limitation the rights |
|
15 | - * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
|
16 | - * copies of the Software, and to permit persons to whom the Software is |
|
17 | - * furnished to do so, subject to the following conditions: |
|
18 | - * |
|
19 | - * The above copyright notice and this permission notice shall be included in |
|
20 | - * all copies or substantial portions of the Software. |
|
21 | - * |
|
22 | - * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
|
23 | - * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
|
24 | - * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
|
25 | - * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
|
26 | - * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
|
27 | - * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE |
|
28 | - * SOFTWARE. |
|
29 | - */ |
|
30 | - |
|
31 | - /** |
|
32 | - * Fetch a random integer between $min and $max inclusive |
|
33 | - * |
|
34 | - * @param int $min |
|
35 | - * @param int $max |
|
36 | - * |
|
37 | - * @throws Exception |
|
38 | - * |
|
39 | - * @return int |
|
40 | - */ |
|
41 | - function random_int($min, $max) |
|
42 | - { |
|
43 | - /** |
|
44 | - * Type and input logic checks |
|
45 | - * |
|
46 | - * If you pass it a float in the range (~PHP_INT_MAX, PHP_INT_MAX) |
|
47 | - * (non-inclusive), it will sanely cast it to an int. If you it's equal to |
|
48 | - * ~PHP_INT_MAX or PHP_INT_MAX, we let it fail as not an integer. Floats |
|
49 | - * lose precision, so the <= and => operators might accidentally let a float |
|
50 | - * through. |
|
51 | - */ |
|
52 | - |
|
53 | - try { |
|
54 | - /** @var int $min */ |
|
55 | - $min = RandomCompat_intval($min); |
|
56 | - } catch (TypeError $ex) { |
|
57 | - throw new TypeError( |
|
58 | - 'random_int(): $min must be an integer' |
|
59 | - ); |
|
60 | - } |
|
61 | - |
|
62 | - try { |
|
63 | - /** @var int $max */ |
|
64 | - $max = RandomCompat_intval($max); |
|
65 | - } catch (TypeError $ex) { |
|
66 | - throw new TypeError( |
|
67 | - 'random_int(): $max must be an integer' |
|
68 | - ); |
|
69 | - } |
|
70 | - |
|
71 | - /** |
|
72 | - * Now that we've verified our weak typing system has given us an integer, |
|
73 | - * let's validate the logic then we can move forward with generating random |
|
74 | - * integers along a given range. |
|
75 | - */ |
|
76 | - if ($min > $max) { |
|
77 | - throw new Error( |
|
78 | - 'Minimum value must be less than or equal to the maximum value' |
|
79 | - ); |
|
80 | - } |
|
81 | - |
|
82 | - if ($max === $min) { |
|
83 | - return (int) $min; |
|
84 | - } |
|
85 | - |
|
86 | - /** |
|
87 | - * Initialize variables to 0 |
|
88 | - * |
|
89 | - * We want to store: |
|
90 | - * $bytes => the number of random bytes we need |
|
91 | - * $mask => an integer bitmask (for use with the &) operator |
|
92 | - * so we can minimize the number of discards |
|
93 | - */ |
|
94 | - $attempts = $bits = $bytes = $mask = $valueShift = 0; |
|
95 | - /** @var int $attempts */ |
|
96 | - /** @var int $bits */ |
|
97 | - /** @var int $bytes */ |
|
98 | - /** @var int $mask */ |
|
99 | - /** @var int $valueShift */ |
|
100 | - |
|
101 | - /** |
|
102 | - * At this point, $range is a positive number greater than 0. It might |
|
103 | - * overflow, however, if $max - $min > PHP_INT_MAX. PHP will cast it to |
|
104 | - * a float and we will lose some precision. |
|
105 | - * |
|
106 | - * @var int|float $range |
|
107 | - */ |
|
108 | - $range = $max - $min; |
|
109 | - |
|
110 | - /** |
|
111 | - * Test for integer overflow: |
|
112 | - */ |
|
113 | - if (!is_int($range)) { |
|
114 | - |
|
115 | - /** |
|
116 | - * Still safely calculate wider ranges. |
|
117 | - * Provided by @CodesInChaos, @oittaa |
|
118 | - * |
|
119 | - * @ref https://gist.github.com/CodesInChaos/03f9ea0b58e8b2b8d435 |
|
120 | - * |
|
121 | - * We use ~0 as a mask in this case because it generates all 1s |
|
122 | - * |
|
123 | - * @ref https://eval.in/400356 (32-bit) |
|
124 | - * @ref http://3v4l.org/XX9r5 (64-bit) |
|
125 | - */ |
|
126 | - $bytes = PHP_INT_SIZE; |
|
127 | - /** @var int $mask */ |
|
128 | - $mask = ~0; |
|
129 | - |
|
130 | - } else { |
|
131 | - |
|
132 | - /** |
|
133 | - * $bits is effectively ceil(log($range, 2)) without dealing with |
|
134 | - * type juggling |
|
135 | - */ |
|
136 | - while ($range > 0) { |
|
137 | - if ($bits % 8 === 0) { |
|
138 | - ++$bytes; |
|
139 | - } |
|
140 | - ++$bits; |
|
141 | - $range >>= 1; |
|
142 | - /** @var int $mask */ |
|
143 | - $mask = $mask << 1 | 1; |
|
144 | - } |
|
145 | - $valueShift = $min; |
|
146 | - } |
|
147 | - |
|
148 | - /** @var int $val */ |
|
149 | - $val = 0; |
|
150 | - /** |
|
151 | - * Now that we have our parameters set up, let's begin generating |
|
152 | - * random integers until one falls between $min and $max |
|
153 | - */ |
|
154 | - /** @psalm-suppress RedundantCondition */ |
|
155 | - do { |
|
156 | - /** |
|
157 | - * The rejection probability is at most 0.5, so this corresponds |
|
158 | - * to a failure probability of 2^-128 for a working RNG |
|
159 | - */ |
|
160 | - if ($attempts > 128) { |
|
161 | - throw new Exception( |
|
162 | - 'random_int: RNG is broken - too many rejections' |
|
163 | - ); |
|
164 | - } |
|
165 | - |
|
166 | - /** |
|
167 | - * Let's grab the necessary number of random bytes |
|
168 | - */ |
|
169 | - $randomByteString = random_bytes($bytes); |
|
170 | - |
|
171 | - /** |
|
172 | - * Let's turn $randomByteString into an integer |
|
173 | - * |
|
174 | - * This uses bitwise operators (<< and |) to build an integer |
|
175 | - * out of the values extracted from ord() |
|
176 | - * |
|
177 | - * Example: [9F] | [6D] | [32] | [0C] => |
|
178 | - * 159 + 27904 + 3276800 + 201326592 => |
|
179 | - * 204631455 |
|
180 | - */ |
|
181 | - $val &= 0; |
|
182 | - for ($i = 0; $i < $bytes; ++$i) { |
|
183 | - $val |= ord($randomByteString[$i]) << ($i * 8); |
|
184 | - } |
|
185 | - /** @var int $val */ |
|
186 | - |
|
187 | - /** |
|
188 | - * Apply mask |
|
189 | - */ |
|
190 | - $val &= $mask; |
|
191 | - $val += $valueShift; |
|
192 | - |
|
193 | - ++$attempts; |
|
194 | - /** |
|
195 | - * If $val overflows to a floating point number, |
|
196 | - * ... or is larger than $max, |
|
197 | - * ... or smaller than $min, |
|
198 | - * then try again. |
|
199 | - */ |
|
200 | - } while (!is_int($val) || $val > $max || $val < $min); |
|
201 | - |
|
202 | - return (int) $val; |
|
203 | - } |
|
4 | + /** |
|
5 | + * Random_* Compatibility Library |
|
6 | + * for using the new PHP 7 random_* API in PHP 5 projects |
|
7 | + * |
|
8 | + * The MIT License (MIT) |
|
9 | + * |
|
10 | + * Copyright (c) 2015 - 2018 Paragon Initiative Enterprises |
|
11 | + * |
|
12 | + * Permission is hereby granted, free of charge, to any person obtaining a copy |
|
13 | + * of this software and associated documentation files (the "Software"), to deal |
|
14 | + * in the Software without restriction, including without limitation the rights |
|
15 | + * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
|
16 | + * copies of the Software, and to permit persons to whom the Software is |
|
17 | + * furnished to do so, subject to the following conditions: |
|
18 | + * |
|
19 | + * The above copyright notice and this permission notice shall be included in |
|
20 | + * all copies or substantial portions of the Software. |
|
21 | + * |
|
22 | + * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
|
23 | + * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
|
24 | + * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
|
25 | + * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
|
26 | + * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
|
27 | + * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE |
|
28 | + * SOFTWARE. |
|
29 | + */ |
|
30 | + |
|
31 | + /** |
|
32 | + * Fetch a random integer between $min and $max inclusive |
|
33 | + * |
|
34 | + * @param int $min |
|
35 | + * @param int $max |
|
36 | + * |
|
37 | + * @throws Exception |
|
38 | + * |
|
39 | + * @return int |
|
40 | + */ |
|
41 | + function random_int($min, $max) |
|
42 | + { |
|
43 | + /** |
|
44 | + * Type and input logic checks |
|
45 | + * |
|
46 | + * If you pass it a float in the range (~PHP_INT_MAX, PHP_INT_MAX) |
|
47 | + * (non-inclusive), it will sanely cast it to an int. If you it's equal to |
|
48 | + * ~PHP_INT_MAX or PHP_INT_MAX, we let it fail as not an integer. Floats |
|
49 | + * lose precision, so the <= and => operators might accidentally let a float |
|
50 | + * through. |
|
51 | + */ |
|
52 | + |
|
53 | + try { |
|
54 | + /** @var int $min */ |
|
55 | + $min = RandomCompat_intval($min); |
|
56 | + } catch (TypeError $ex) { |
|
57 | + throw new TypeError( |
|
58 | + 'random_int(): $min must be an integer' |
|
59 | + ); |
|
60 | + } |
|
61 | + |
|
62 | + try { |
|
63 | + /** @var int $max */ |
|
64 | + $max = RandomCompat_intval($max); |
|
65 | + } catch (TypeError $ex) { |
|
66 | + throw new TypeError( |
|
67 | + 'random_int(): $max must be an integer' |
|
68 | + ); |
|
69 | + } |
|
70 | + |
|
71 | + /** |
|
72 | + * Now that we've verified our weak typing system has given us an integer, |
|
73 | + * let's validate the logic then we can move forward with generating random |
|
74 | + * integers along a given range. |
|
75 | + */ |
|
76 | + if ($min > $max) { |
|
77 | + throw new Error( |
|
78 | + 'Minimum value must be less than or equal to the maximum value' |
|
79 | + ); |
|
80 | + } |
|
81 | + |
|
82 | + if ($max === $min) { |
|
83 | + return (int) $min; |
|
84 | + } |
|
85 | + |
|
86 | + /** |
|
87 | + * Initialize variables to 0 |
|
88 | + * |
|
89 | + * We want to store: |
|
90 | + * $bytes => the number of random bytes we need |
|
91 | + * $mask => an integer bitmask (for use with the &) operator |
|
92 | + * so we can minimize the number of discards |
|
93 | + */ |
|
94 | + $attempts = $bits = $bytes = $mask = $valueShift = 0; |
|
95 | + /** @var int $attempts */ |
|
96 | + /** @var int $bits */ |
|
97 | + /** @var int $bytes */ |
|
98 | + /** @var int $mask */ |
|
99 | + /** @var int $valueShift */ |
|
100 | + |
|
101 | + /** |
|
102 | + * At this point, $range is a positive number greater than 0. It might |
|
103 | + * overflow, however, if $max - $min > PHP_INT_MAX. PHP will cast it to |
|
104 | + * a float and we will lose some precision. |
|
105 | + * |
|
106 | + * @var int|float $range |
|
107 | + */ |
|
108 | + $range = $max - $min; |
|
109 | + |
|
110 | + /** |
|
111 | + * Test for integer overflow: |
|
112 | + */ |
|
113 | + if (!is_int($range)) { |
|
114 | + |
|
115 | + /** |
|
116 | + * Still safely calculate wider ranges. |
|
117 | + * Provided by @CodesInChaos, @oittaa |
|
118 | + * |
|
119 | + * @ref https://gist.github.com/CodesInChaos/03f9ea0b58e8b2b8d435 |
|
120 | + * |
|
121 | + * We use ~0 as a mask in this case because it generates all 1s |
|
122 | + * |
|
123 | + * @ref https://eval.in/400356 (32-bit) |
|
124 | + * @ref http://3v4l.org/XX9r5 (64-bit) |
|
125 | + */ |
|
126 | + $bytes = PHP_INT_SIZE; |
|
127 | + /** @var int $mask */ |
|
128 | + $mask = ~0; |
|
129 | + |
|
130 | + } else { |
|
131 | + |
|
132 | + /** |
|
133 | + * $bits is effectively ceil(log($range, 2)) without dealing with |
|
134 | + * type juggling |
|
135 | + */ |
|
136 | + while ($range > 0) { |
|
137 | + if ($bits % 8 === 0) { |
|
138 | + ++$bytes; |
|
139 | + } |
|
140 | + ++$bits; |
|
141 | + $range >>= 1; |
|
142 | + /** @var int $mask */ |
|
143 | + $mask = $mask << 1 | 1; |
|
144 | + } |
|
145 | + $valueShift = $min; |
|
146 | + } |
|
147 | + |
|
148 | + /** @var int $val */ |
|
149 | + $val = 0; |
|
150 | + /** |
|
151 | + * Now that we have our parameters set up, let's begin generating |
|
152 | + * random integers until one falls between $min and $max |
|
153 | + */ |
|
154 | + /** @psalm-suppress RedundantCondition */ |
|
155 | + do { |
|
156 | + /** |
|
157 | + * The rejection probability is at most 0.5, so this corresponds |
|
158 | + * to a failure probability of 2^-128 for a working RNG |
|
159 | + */ |
|
160 | + if ($attempts > 128) { |
|
161 | + throw new Exception( |
|
162 | + 'random_int: RNG is broken - too many rejections' |
|
163 | + ); |
|
164 | + } |
|
165 | + |
|
166 | + /** |
|
167 | + * Let's grab the necessary number of random bytes |
|
168 | + */ |
|
169 | + $randomByteString = random_bytes($bytes); |
|
170 | + |
|
171 | + /** |
|
172 | + * Let's turn $randomByteString into an integer |
|
173 | + * |
|
174 | + * This uses bitwise operators (<< and |) to build an integer |
|
175 | + * out of the values extracted from ord() |
|
176 | + * |
|
177 | + * Example: [9F] | [6D] | [32] | [0C] => |
|
178 | + * 159 + 27904 + 3276800 + 201326592 => |
|
179 | + * 204631455 |
|
180 | + */ |
|
181 | + $val &= 0; |
|
182 | + for ($i = 0; $i < $bytes; ++$i) { |
|
183 | + $val |= ord($randomByteString[$i]) << ($i * 8); |
|
184 | + } |
|
185 | + /** @var int $val */ |
|
186 | + |
|
187 | + /** |
|
188 | + * Apply mask |
|
189 | + */ |
|
190 | + $val &= $mask; |
|
191 | + $val += $valueShift; |
|
192 | + |
|
193 | + ++$attempts; |
|
194 | + /** |
|
195 | + * If $val overflows to a floating point number, |
|
196 | + * ... or is larger than $max, |
|
197 | + * ... or smaller than $min, |
|
198 | + * then try again. |
|
199 | + */ |
|
200 | + } while (!is_int($val) || $val > $max || $val < $min); |
|
201 | + |
|
202 | + return (int) $val; |
|
203 | + } |
|
204 | 204 | } |
@@ -27,53 +27,53 @@ |
||
27 | 27 | */ |
28 | 28 | |
29 | 29 | if (!is_callable('random_bytes')) { |
30 | - /** |
|
31 | - * Powered by ext/mcrypt (and thankfully NOT libmcrypt) |
|
32 | - * |
|
33 | - * @ref https://bugs.php.net/bug.php?id=55169 |
|
34 | - * @ref https://github.com/php/php-src/blob/c568ffe5171d942161fc8dda066bce844bdef676/ext/mcrypt/mcrypt.c#L1321-L1386 |
|
35 | - * |
|
36 | - * @param int $bytes |
|
37 | - * |
|
38 | - * @throws Exception |
|
39 | - * |
|
40 | - * @return string |
|
41 | - */ |
|
42 | - function random_bytes($bytes) |
|
43 | - { |
|
44 | - try { |
|
45 | - /** @var int $bytes */ |
|
46 | - $bytes = RandomCompat_intval($bytes); |
|
47 | - } catch (TypeError $ex) { |
|
48 | - throw new TypeError( |
|
49 | - 'random_bytes(): $bytes must be an integer' |
|
50 | - ); |
|
51 | - } |
|
30 | + /** |
|
31 | + * Powered by ext/mcrypt (and thankfully NOT libmcrypt) |
|
32 | + * |
|
33 | + * @ref https://bugs.php.net/bug.php?id=55169 |
|
34 | + * @ref https://github.com/php/php-src/blob/c568ffe5171d942161fc8dda066bce844bdef676/ext/mcrypt/mcrypt.c#L1321-L1386 |
|
35 | + * |
|
36 | + * @param int $bytes |
|
37 | + * |
|
38 | + * @throws Exception |
|
39 | + * |
|
40 | + * @return string |
|
41 | + */ |
|
42 | + function random_bytes($bytes) |
|
43 | + { |
|
44 | + try { |
|
45 | + /** @var int $bytes */ |
|
46 | + $bytes = RandomCompat_intval($bytes); |
|
47 | + } catch (TypeError $ex) { |
|
48 | + throw new TypeError( |
|
49 | + 'random_bytes(): $bytes must be an integer' |
|
50 | + ); |
|
51 | + } |
|
52 | 52 | |
53 | - if ($bytes < 1) { |
|
54 | - throw new Error( |
|
55 | - 'Length must be greater than 0' |
|
56 | - ); |
|
57 | - } |
|
53 | + if ($bytes < 1) { |
|
54 | + throw new Error( |
|
55 | + 'Length must be greater than 0' |
|
56 | + ); |
|
57 | + } |
|
58 | 58 | |
59 | - /** @var string|bool $buf */ |
|
60 | - $buf = @mcrypt_create_iv((int) $bytes, (int) MCRYPT_DEV_URANDOM); |
|
61 | - if ( |
|
62 | - is_string($buf) |
|
63 | - && |
|
64 | - RandomCompat_strlen($buf) === $bytes |
|
65 | - ) { |
|
66 | - /** |
|
67 | - * Return our random entropy buffer here: |
|
68 | - */ |
|
69 | - return $buf; |
|
70 | - } |
|
59 | + /** @var string|bool $buf */ |
|
60 | + $buf = @mcrypt_create_iv((int) $bytes, (int) MCRYPT_DEV_URANDOM); |
|
61 | + if ( |
|
62 | + is_string($buf) |
|
63 | + && |
|
64 | + RandomCompat_strlen($buf) === $bytes |
|
65 | + ) { |
|
66 | + /** |
|
67 | + * Return our random entropy buffer here: |
|
68 | + */ |
|
69 | + return $buf; |
|
70 | + } |
|
71 | 71 | |
72 | - /** |
|
73 | - * If we reach here, PHP has failed us. |
|
74 | - */ |
|
75 | - throw new Exception( |
|
76 | - 'Could not gather sufficient random data' |
|
77 | - ); |
|
78 | - } |
|
72 | + /** |
|
73 | + * If we reach here, PHP has failed us. |
|
74 | + */ |
|
75 | + throw new Exception( |
|
76 | + 'Could not gather sufficient random data' |
|
77 | + ); |
|
78 | + } |
|
79 | 79 | } |
@@ -27,146 +27,146 @@ |
||
27 | 27 | */ |
28 | 28 | |
29 | 29 | if (!defined('RANDOM_COMPAT_READ_BUFFER')) { |
30 | - define('RANDOM_COMPAT_READ_BUFFER', 8); |
|
30 | + define('RANDOM_COMPAT_READ_BUFFER', 8); |
|
31 | 31 | } |
32 | 32 | |
33 | 33 | if (!is_callable('random_bytes')) { |
34 | - /** |
|
35 | - * Unless open_basedir is enabled, use /dev/urandom for |
|
36 | - * random numbers in accordance with best practices |
|
37 | - * |
|
38 | - * Why we use /dev/urandom and not /dev/random |
|
39 | - * @ref http://sockpuppet.org/blog/2014/02/25/safely-generate-random-numbers |
|
40 | - * |
|
41 | - * @param int $bytes |
|
42 | - * |
|
43 | - * @throws Exception |
|
44 | - * |
|
45 | - * @return string |
|
46 | - */ |
|
47 | - function random_bytes($bytes) |
|
48 | - { |
|
49 | - /** @var resource $fp */ |
|
50 | - static $fp = null; |
|
34 | + /** |
|
35 | + * Unless open_basedir is enabled, use /dev/urandom for |
|
36 | + * random numbers in accordance with best practices |
|
37 | + * |
|
38 | + * Why we use /dev/urandom and not /dev/random |
|
39 | + * @ref http://sockpuppet.org/blog/2014/02/25/safely-generate-random-numbers |
|
40 | + * |
|
41 | + * @param int $bytes |
|
42 | + * |
|
43 | + * @throws Exception |
|
44 | + * |
|
45 | + * @return string |
|
46 | + */ |
|
47 | + function random_bytes($bytes) |
|
48 | + { |
|
49 | + /** @var resource $fp */ |
|
50 | + static $fp = null; |
|
51 | 51 | |
52 | - /** |
|
53 | - * This block should only be run once |
|
54 | - */ |
|
55 | - if (empty($fp)) { |
|
56 | - /** |
|
57 | - * We use /dev/urandom if it is a char device. |
|
58 | - * We never fall back to /dev/random |
|
59 | - */ |
|
60 | - /** @var resource|bool $fp */ |
|
61 | - $fp = fopen('/dev/urandom', 'rb'); |
|
62 | - if (is_resource($fp)) { |
|
63 | - /** @var array<string, int> $st */ |
|
64 | - $st = fstat($fp); |
|
65 | - if (($st['mode'] & 0170000) !== 020000) { |
|
66 | - fclose($fp); |
|
67 | - $fp = false; |
|
68 | - } |
|
69 | - } |
|
52 | + /** |
|
53 | + * This block should only be run once |
|
54 | + */ |
|
55 | + if (empty($fp)) { |
|
56 | + /** |
|
57 | + * We use /dev/urandom if it is a char device. |
|
58 | + * We never fall back to /dev/random |
|
59 | + */ |
|
60 | + /** @var resource|bool $fp */ |
|
61 | + $fp = fopen('/dev/urandom', 'rb'); |
|
62 | + if (is_resource($fp)) { |
|
63 | + /** @var array<string, int> $st */ |
|
64 | + $st = fstat($fp); |
|
65 | + if (($st['mode'] & 0170000) !== 020000) { |
|
66 | + fclose($fp); |
|
67 | + $fp = false; |
|
68 | + } |
|
69 | + } |
|
70 | 70 | |
71 | - if (is_resource($fp)) { |
|
72 | - /** |
|
73 | - * stream_set_read_buffer() does not exist in HHVM |
|
74 | - * |
|
75 | - * If we don't set the stream's read buffer to 0, PHP will |
|
76 | - * internally buffer 8192 bytes, which can waste entropy |
|
77 | - * |
|
78 | - * stream_set_read_buffer returns 0 on success |
|
79 | - */ |
|
80 | - if (is_callable('stream_set_read_buffer')) { |
|
81 | - stream_set_read_buffer($fp, RANDOM_COMPAT_READ_BUFFER); |
|
82 | - } |
|
83 | - if (is_callable('stream_set_chunk_size')) { |
|
84 | - stream_set_chunk_size($fp, RANDOM_COMPAT_READ_BUFFER); |
|
85 | - } |
|
86 | - } |
|
87 | - } |
|
71 | + if (is_resource($fp)) { |
|
72 | + /** |
|
73 | + * stream_set_read_buffer() does not exist in HHVM |
|
74 | + * |
|
75 | + * If we don't set the stream's read buffer to 0, PHP will |
|
76 | + * internally buffer 8192 bytes, which can waste entropy |
|
77 | + * |
|
78 | + * stream_set_read_buffer returns 0 on success |
|
79 | + */ |
|
80 | + if (is_callable('stream_set_read_buffer')) { |
|
81 | + stream_set_read_buffer($fp, RANDOM_COMPAT_READ_BUFFER); |
|
82 | + } |
|
83 | + if (is_callable('stream_set_chunk_size')) { |
|
84 | + stream_set_chunk_size($fp, RANDOM_COMPAT_READ_BUFFER); |
|
85 | + } |
|
86 | + } |
|
87 | + } |
|
88 | 88 | |
89 | - try { |
|
90 | - /** @var int $bytes */ |
|
91 | - $bytes = RandomCompat_intval($bytes); |
|
92 | - } catch (TypeError $ex) { |
|
93 | - throw new TypeError( |
|
94 | - 'random_bytes(): $bytes must be an integer' |
|
95 | - ); |
|
96 | - } |
|
89 | + try { |
|
90 | + /** @var int $bytes */ |
|
91 | + $bytes = RandomCompat_intval($bytes); |
|
92 | + } catch (TypeError $ex) { |
|
93 | + throw new TypeError( |
|
94 | + 'random_bytes(): $bytes must be an integer' |
|
95 | + ); |
|
96 | + } |
|
97 | 97 | |
98 | - if ($bytes < 1) { |
|
99 | - throw new Error( |
|
100 | - 'Length must be greater than 0' |
|
101 | - ); |
|
102 | - } |
|
98 | + if ($bytes < 1) { |
|
99 | + throw new Error( |
|
100 | + 'Length must be greater than 0' |
|
101 | + ); |
|
102 | + } |
|
103 | 103 | |
104 | - /** |
|
105 | - * This if() block only runs if we managed to open a file handle |
|
106 | - * |
|
107 | - * It does not belong in an else {} block, because the above |
|
108 | - * if (empty($fp)) line is logic that should only be run once per |
|
109 | - * page load. |
|
110 | - */ |
|
111 | - if (is_resource($fp)) { |
|
112 | - /** |
|
113 | - * @var int |
|
114 | - */ |
|
115 | - $remaining = $bytes; |
|
104 | + /** |
|
105 | + * This if() block only runs if we managed to open a file handle |
|
106 | + * |
|
107 | + * It does not belong in an else {} block, because the above |
|
108 | + * if (empty($fp)) line is logic that should only be run once per |
|
109 | + * page load. |
|
110 | + */ |
|
111 | + if (is_resource($fp)) { |
|
112 | + /** |
|
113 | + * @var int |
|
114 | + */ |
|
115 | + $remaining = $bytes; |
|
116 | 116 | |
117 | - /** |
|
118 | - * @var string|bool |
|
119 | - */ |
|
120 | - $buf = ''; |
|
117 | + /** |
|
118 | + * @var string|bool |
|
119 | + */ |
|
120 | + $buf = ''; |
|
121 | 121 | |
122 | - /** |
|
123 | - * We use fread() in a loop to protect against partial reads |
|
124 | - */ |
|
125 | - do { |
|
126 | - /** |
|
127 | - * @var string|bool |
|
128 | - */ |
|
129 | - $read = fread($fp, $remaining); |
|
130 | - if (!is_string($read)) { |
|
131 | - if ($read === false) { |
|
132 | - /** |
|
133 | - * We cannot safely read from the file. Exit the |
|
134 | - * do-while loop and trigger the exception condition |
|
135 | - * |
|
136 | - * @var string|bool |
|
137 | - */ |
|
138 | - $buf = false; |
|
139 | - break; |
|
140 | - } |
|
141 | - } |
|
142 | - /** |
|
143 | - * Decrease the number of bytes returned from remaining |
|
144 | - */ |
|
145 | - $remaining -= RandomCompat_strlen($read); |
|
146 | - /** |
|
147 | - * @var string|bool |
|
148 | - */ |
|
149 | - $buf = $buf . $read; |
|
150 | - } while ($remaining > 0); |
|
122 | + /** |
|
123 | + * We use fread() in a loop to protect against partial reads |
|
124 | + */ |
|
125 | + do { |
|
126 | + /** |
|
127 | + * @var string|bool |
|
128 | + */ |
|
129 | + $read = fread($fp, $remaining); |
|
130 | + if (!is_string($read)) { |
|
131 | + if ($read === false) { |
|
132 | + /** |
|
133 | + * We cannot safely read from the file. Exit the |
|
134 | + * do-while loop and trigger the exception condition |
|
135 | + * |
|
136 | + * @var string|bool |
|
137 | + */ |
|
138 | + $buf = false; |
|
139 | + break; |
|
140 | + } |
|
141 | + } |
|
142 | + /** |
|
143 | + * Decrease the number of bytes returned from remaining |
|
144 | + */ |
|
145 | + $remaining -= RandomCompat_strlen($read); |
|
146 | + /** |
|
147 | + * @var string|bool |
|
148 | + */ |
|
149 | + $buf = $buf . $read; |
|
150 | + } while ($remaining > 0); |
|
151 | 151 | |
152 | - /** |
|
153 | - * Is our result valid? |
|
154 | - */ |
|
155 | - if (is_string($buf)) { |
|
156 | - if (RandomCompat_strlen($buf) === $bytes) { |
|
157 | - /** |
|
158 | - * Return our random entropy buffer here: |
|
159 | - */ |
|
160 | - return $buf; |
|
161 | - } |
|
162 | - } |
|
163 | - } |
|
152 | + /** |
|
153 | + * Is our result valid? |
|
154 | + */ |
|
155 | + if (is_string($buf)) { |
|
156 | + if (RandomCompat_strlen($buf) === $bytes) { |
|
157 | + /** |
|
158 | + * Return our random entropy buffer here: |
|
159 | + */ |
|
160 | + return $buf; |
|
161 | + } |
|
162 | + } |
|
163 | + } |
|
164 | 164 | |
165 | - /** |
|
166 | - * If we reach here, PHP has failed us. |
|
167 | - */ |
|
168 | - throw new Exception( |
|
169 | - 'Error reading from source device' |
|
170 | - ); |
|
171 | - } |
|
165 | + /** |
|
166 | + * If we reach here, PHP has failed us. |
|
167 | + */ |
|
168 | + throw new Exception( |
|
169 | + 'Error reading from source device' |
|
170 | + ); |
|
171 | + } |
|
172 | 172 | } |
@@ -27,169 +27,169 @@ |
||
27 | 27 | */ |
28 | 28 | |
29 | 29 | if (!is_callable('RandomCompat_strlen')) { |
30 | - if ( |
|
31 | - defined('MB_OVERLOAD_STRING') |
|
32 | - && |
|
33 | - ((int) ini_get('mbstring.func_overload')) & MB_OVERLOAD_STRING |
|
34 | - ) { |
|
35 | - /** |
|
36 | - * strlen() implementation that isn't brittle to mbstring.func_overload |
|
37 | - * |
|
38 | - * This version uses mb_strlen() in '8bit' mode to treat strings as raw |
|
39 | - * binary rather than UTF-8, ISO-8859-1, etc |
|
40 | - * |
|
41 | - * @param string $binary_string |
|
42 | - * |
|
43 | - * @throws TypeError |
|
44 | - * |
|
45 | - * @return int |
|
46 | - */ |
|
47 | - function RandomCompat_strlen($binary_string) |
|
48 | - { |
|
49 | - if (!is_string($binary_string)) { |
|
50 | - throw new TypeError( |
|
51 | - 'RandomCompat_strlen() expects a string' |
|
52 | - ); |
|
53 | - } |
|
30 | + if ( |
|
31 | + defined('MB_OVERLOAD_STRING') |
|
32 | + && |
|
33 | + ((int) ini_get('mbstring.func_overload')) & MB_OVERLOAD_STRING |
|
34 | + ) { |
|
35 | + /** |
|
36 | + * strlen() implementation that isn't brittle to mbstring.func_overload |
|
37 | + * |
|
38 | + * This version uses mb_strlen() in '8bit' mode to treat strings as raw |
|
39 | + * binary rather than UTF-8, ISO-8859-1, etc |
|
40 | + * |
|
41 | + * @param string $binary_string |
|
42 | + * |
|
43 | + * @throws TypeError |
|
44 | + * |
|
45 | + * @return int |
|
46 | + */ |
|
47 | + function RandomCompat_strlen($binary_string) |
|
48 | + { |
|
49 | + if (!is_string($binary_string)) { |
|
50 | + throw new TypeError( |
|
51 | + 'RandomCompat_strlen() expects a string' |
|
52 | + ); |
|
53 | + } |
|
54 | 54 | |
55 | - return (int) mb_strlen($binary_string, '8bit'); |
|
56 | - } |
|
55 | + return (int) mb_strlen($binary_string, '8bit'); |
|
56 | + } |
|
57 | 57 | |
58 | - } else { |
|
59 | - /** |
|
60 | - * strlen() implementation that isn't brittle to mbstring.func_overload |
|
61 | - * |
|
62 | - * This version just used the default strlen() |
|
63 | - * |
|
64 | - * @param string $binary_string |
|
65 | - * |
|
66 | - * @throws TypeError |
|
67 | - * |
|
68 | - * @return int |
|
69 | - */ |
|
70 | - function RandomCompat_strlen($binary_string) |
|
71 | - { |
|
72 | - if (!is_string($binary_string)) { |
|
73 | - throw new TypeError( |
|
74 | - 'RandomCompat_strlen() expects a string' |
|
75 | - ); |
|
76 | - } |
|
77 | - return (int) strlen($binary_string); |
|
78 | - } |
|
79 | - } |
|
58 | + } else { |
|
59 | + /** |
|
60 | + * strlen() implementation that isn't brittle to mbstring.func_overload |
|
61 | + * |
|
62 | + * This version just used the default strlen() |
|
63 | + * |
|
64 | + * @param string $binary_string |
|
65 | + * |
|
66 | + * @throws TypeError |
|
67 | + * |
|
68 | + * @return int |
|
69 | + */ |
|
70 | + function RandomCompat_strlen($binary_string) |
|
71 | + { |
|
72 | + if (!is_string($binary_string)) { |
|
73 | + throw new TypeError( |
|
74 | + 'RandomCompat_strlen() expects a string' |
|
75 | + ); |
|
76 | + } |
|
77 | + return (int) strlen($binary_string); |
|
78 | + } |
|
79 | + } |
|
80 | 80 | } |
81 | 81 | |
82 | 82 | if (!is_callable('RandomCompat_substr')) { |
83 | 83 | |
84 | - if ( |
|
85 | - defined('MB_OVERLOAD_STRING') |
|
86 | - && |
|
87 | - ((int) ini_get('mbstring.func_overload')) & MB_OVERLOAD_STRING |
|
88 | - ) { |
|
89 | - /** |
|
90 | - * substr() implementation that isn't brittle to mbstring.func_overload |
|
91 | - * |
|
92 | - * This version uses mb_substr() in '8bit' mode to treat strings as raw |
|
93 | - * binary rather than UTF-8, ISO-8859-1, etc |
|
94 | - * |
|
95 | - * @param string $binary_string |
|
96 | - * @param int $start |
|
97 | - * @param int|null $length (optional) |
|
98 | - * |
|
99 | - * @throws TypeError |
|
100 | - * |
|
101 | - * @return string |
|
102 | - */ |
|
103 | - function RandomCompat_substr($binary_string, $start, $length = null) |
|
104 | - { |
|
105 | - if (!is_string($binary_string)) { |
|
106 | - throw new TypeError( |
|
107 | - 'RandomCompat_substr(): First argument should be a string' |
|
108 | - ); |
|
109 | - } |
|
84 | + if ( |
|
85 | + defined('MB_OVERLOAD_STRING') |
|
86 | + && |
|
87 | + ((int) ini_get('mbstring.func_overload')) & MB_OVERLOAD_STRING |
|
88 | + ) { |
|
89 | + /** |
|
90 | + * substr() implementation that isn't brittle to mbstring.func_overload |
|
91 | + * |
|
92 | + * This version uses mb_substr() in '8bit' mode to treat strings as raw |
|
93 | + * binary rather than UTF-8, ISO-8859-1, etc |
|
94 | + * |
|
95 | + * @param string $binary_string |
|
96 | + * @param int $start |
|
97 | + * @param int|null $length (optional) |
|
98 | + * |
|
99 | + * @throws TypeError |
|
100 | + * |
|
101 | + * @return string |
|
102 | + */ |
|
103 | + function RandomCompat_substr($binary_string, $start, $length = null) |
|
104 | + { |
|
105 | + if (!is_string($binary_string)) { |
|
106 | + throw new TypeError( |
|
107 | + 'RandomCompat_substr(): First argument should be a string' |
|
108 | + ); |
|
109 | + } |
|
110 | 110 | |
111 | - if (!is_int($start)) { |
|
112 | - throw new TypeError( |
|
113 | - 'RandomCompat_substr(): Second argument should be an integer' |
|
114 | - ); |
|
115 | - } |
|
111 | + if (!is_int($start)) { |
|
112 | + throw new TypeError( |
|
113 | + 'RandomCompat_substr(): Second argument should be an integer' |
|
114 | + ); |
|
115 | + } |
|
116 | 116 | |
117 | - if ($length === null) { |
|
118 | - /** |
|
119 | - * mb_substr($str, 0, NULL, '8bit') returns an empty string on |
|
120 | - * PHP 5.3, so we have to find the length ourselves. |
|
121 | - */ |
|
122 | - /** @var int $length */ |
|
123 | - $length = RandomCompat_strlen($binary_string) - $start; |
|
124 | - } elseif (!is_int($length)) { |
|
125 | - throw new TypeError( |
|
126 | - 'RandomCompat_substr(): Third argument should be an integer, or omitted' |
|
127 | - ); |
|
128 | - } |
|
117 | + if ($length === null) { |
|
118 | + /** |
|
119 | + * mb_substr($str, 0, NULL, '8bit') returns an empty string on |
|
120 | + * PHP 5.3, so we have to find the length ourselves. |
|
121 | + */ |
|
122 | + /** @var int $length */ |
|
123 | + $length = RandomCompat_strlen($binary_string) - $start; |
|
124 | + } elseif (!is_int($length)) { |
|
125 | + throw new TypeError( |
|
126 | + 'RandomCompat_substr(): Third argument should be an integer, or omitted' |
|
127 | + ); |
|
128 | + } |
|
129 | 129 | |
130 | - // Consistency with PHP's behavior |
|
131 | - if ($start === RandomCompat_strlen($binary_string) && $length === 0) { |
|
132 | - return ''; |
|
133 | - } |
|
134 | - if ($start > RandomCompat_strlen($binary_string)) { |
|
135 | - return ''; |
|
136 | - } |
|
130 | + // Consistency with PHP's behavior |
|
131 | + if ($start === RandomCompat_strlen($binary_string) && $length === 0) { |
|
132 | + return ''; |
|
133 | + } |
|
134 | + if ($start > RandomCompat_strlen($binary_string)) { |
|
135 | + return ''; |
|
136 | + } |
|
137 | 137 | |
138 | - return (string) mb_substr( |
|
139 | - (string) $binary_string, |
|
140 | - (int) $start, |
|
141 | - (int) $length, |
|
142 | - '8bit' |
|
143 | - ); |
|
144 | - } |
|
138 | + return (string) mb_substr( |
|
139 | + (string) $binary_string, |
|
140 | + (int) $start, |
|
141 | + (int) $length, |
|
142 | + '8bit' |
|
143 | + ); |
|
144 | + } |
|
145 | 145 | |
146 | - } else { |
|
146 | + } else { |
|
147 | 147 | |
148 | - /** |
|
149 | - * substr() implementation that isn't brittle to mbstring.func_overload |
|
150 | - * |
|
151 | - * This version just uses the default substr() |
|
152 | - * |
|
153 | - * @param string $binary_string |
|
154 | - * @param int $start |
|
155 | - * @param int|null $length (optional) |
|
156 | - * |
|
157 | - * @throws TypeError |
|
158 | - * |
|
159 | - * @return string |
|
160 | - */ |
|
161 | - function RandomCompat_substr($binary_string, $start, $length = null) |
|
162 | - { |
|
163 | - if (!is_string($binary_string)) { |
|
164 | - throw new TypeError( |
|
165 | - 'RandomCompat_substr(): First argument should be a string' |
|
166 | - ); |
|
167 | - } |
|
148 | + /** |
|
149 | + * substr() implementation that isn't brittle to mbstring.func_overload |
|
150 | + * |
|
151 | + * This version just uses the default substr() |
|
152 | + * |
|
153 | + * @param string $binary_string |
|
154 | + * @param int $start |
|
155 | + * @param int|null $length (optional) |
|
156 | + * |
|
157 | + * @throws TypeError |
|
158 | + * |
|
159 | + * @return string |
|
160 | + */ |
|
161 | + function RandomCompat_substr($binary_string, $start, $length = null) |
|
162 | + { |
|
163 | + if (!is_string($binary_string)) { |
|
164 | + throw new TypeError( |
|
165 | + 'RandomCompat_substr(): First argument should be a string' |
|
166 | + ); |
|
167 | + } |
|
168 | 168 | |
169 | - if (!is_int($start)) { |
|
170 | - throw new TypeError( |
|
171 | - 'RandomCompat_substr(): Second argument should be an integer' |
|
172 | - ); |
|
173 | - } |
|
169 | + if (!is_int($start)) { |
|
170 | + throw new TypeError( |
|
171 | + 'RandomCompat_substr(): Second argument should be an integer' |
|
172 | + ); |
|
173 | + } |
|
174 | 174 | |
175 | - if ($length !== null) { |
|
176 | - if (!is_int($length)) { |
|
177 | - throw new TypeError( |
|
178 | - 'RandomCompat_substr(): Third argument should be an integer, or omitted' |
|
179 | - ); |
|
180 | - } |
|
175 | + if ($length !== null) { |
|
176 | + if (!is_int($length)) { |
|
177 | + throw new TypeError( |
|
178 | + 'RandomCompat_substr(): Third argument should be an integer, or omitted' |
|
179 | + ); |
|
180 | + } |
|
181 | 181 | |
182 | - return (string) substr( |
|
183 | - (string )$binary_string, |
|
184 | - (int) $start, |
|
185 | - (int) $length |
|
186 | - ); |
|
187 | - } |
|
182 | + return (string) substr( |
|
183 | + (string )$binary_string, |
|
184 | + (int) $start, |
|
185 | + (int) $length |
|
186 | + ); |
|
187 | + } |
|
188 | 188 | |
189 | - return (string) substr( |
|
190 | - (string) $binary_string, |
|
191 | - (int) $start |
|
192 | - ); |
|
193 | - } |
|
194 | - } |
|
189 | + return (string) substr( |
|
190 | + (string) $binary_string, |
|
191 | + (int) $start |
|
192 | + ); |
|
193 | + } |
|
194 | + } |
|
195 | 195 | } |
@@ -27,65 +27,65 @@ |
||
27 | 27 | */ |
28 | 28 | |
29 | 29 | if (!is_callable('random_bytes')) { |
30 | - /** |
|
31 | - * Windows with PHP < 5.3.0 will not have the function |
|
32 | - * openssl_random_pseudo_bytes() available, so let's use |
|
33 | - * CAPICOM to work around this deficiency. |
|
34 | - * |
|
35 | - * @param int $bytes |
|
36 | - * |
|
37 | - * @throws Exception |
|
38 | - * |
|
39 | - * @return string |
|
40 | - */ |
|
41 | - function random_bytes($bytes) |
|
42 | - { |
|
43 | - try { |
|
44 | - /** @var int $bytes */ |
|
45 | - $bytes = RandomCompat_intval($bytes); |
|
46 | - } catch (TypeError $ex) { |
|
47 | - throw new TypeError( |
|
48 | - 'random_bytes(): $bytes must be an integer' |
|
49 | - ); |
|
50 | - } |
|
30 | + /** |
|
31 | + * Windows with PHP < 5.3.0 will not have the function |
|
32 | + * openssl_random_pseudo_bytes() available, so let's use |
|
33 | + * CAPICOM to work around this deficiency. |
|
34 | + * |
|
35 | + * @param int $bytes |
|
36 | + * |
|
37 | + * @throws Exception |
|
38 | + * |
|
39 | + * @return string |
|
40 | + */ |
|
41 | + function random_bytes($bytes) |
|
42 | + { |
|
43 | + try { |
|
44 | + /** @var int $bytes */ |
|
45 | + $bytes = RandomCompat_intval($bytes); |
|
46 | + } catch (TypeError $ex) { |
|
47 | + throw new TypeError( |
|
48 | + 'random_bytes(): $bytes must be an integer' |
|
49 | + ); |
|
50 | + } |
|
51 | 51 | |
52 | - if ($bytes < 1) { |
|
53 | - throw new Error( |
|
54 | - 'Length must be greater than 0' |
|
55 | - ); |
|
56 | - } |
|
52 | + if ($bytes < 1) { |
|
53 | + throw new Error( |
|
54 | + 'Length must be greater than 0' |
|
55 | + ); |
|
56 | + } |
|
57 | 57 | |
58 | - /** @var string $buf */ |
|
59 | - $buf = ''; |
|
60 | - if (!class_exists('COM')) { |
|
61 | - throw new Error( |
|
62 | - 'COM does not exist' |
|
63 | - ); |
|
64 | - } |
|
65 | - /** @var COM $util */ |
|
66 | - $util = new COM('CAPICOM.Utilities.1'); |
|
67 | - $execCount = 0; |
|
58 | + /** @var string $buf */ |
|
59 | + $buf = ''; |
|
60 | + if (!class_exists('COM')) { |
|
61 | + throw new Error( |
|
62 | + 'COM does not exist' |
|
63 | + ); |
|
64 | + } |
|
65 | + /** @var COM $util */ |
|
66 | + $util = new COM('CAPICOM.Utilities.1'); |
|
67 | + $execCount = 0; |
|
68 | 68 | |
69 | - /** |
|
70 | - * Let's not let it loop forever. If we run N times and fail to |
|
71 | - * get N bytes of random data, then CAPICOM has failed us. |
|
72 | - */ |
|
73 | - do { |
|
74 | - $buf .= base64_decode((string) $util->GetRandom($bytes, 0)); |
|
75 | - if (RandomCompat_strlen($buf) >= $bytes) { |
|
76 | - /** |
|
77 | - * Return our random entropy buffer here: |
|
78 | - */ |
|
79 | - return (string) RandomCompat_substr($buf, 0, $bytes); |
|
80 | - } |
|
81 | - ++$execCount; |
|
82 | - } while ($execCount < $bytes); |
|
69 | + /** |
|
70 | + * Let's not let it loop forever. If we run N times and fail to |
|
71 | + * get N bytes of random data, then CAPICOM has failed us. |
|
72 | + */ |
|
73 | + do { |
|
74 | + $buf .= base64_decode((string) $util->GetRandom($bytes, 0)); |
|
75 | + if (RandomCompat_strlen($buf) >= $bytes) { |
|
76 | + /** |
|
77 | + * Return our random entropy buffer here: |
|
78 | + */ |
|
79 | + return (string) RandomCompat_substr($buf, 0, $bytes); |
|
80 | + } |
|
81 | + ++$execCount; |
|
82 | + } while ($execCount < $bytes); |
|
83 | 83 | |
84 | - /** |
|
85 | - * If we reach here, PHP has failed us. |
|
86 | - */ |
|
87 | - throw new Exception( |
|
88 | - 'Could not gather sufficient random data' |
|
89 | - ); |
|
90 | - } |
|
84 | + /** |
|
85 | + * If we reach here, PHP has failed us. |
|
86 | + */ |
|
87 | + throw new Exception( |
|
88 | + 'Could not gather sufficient random data' |
|
89 | + ); |
|
90 | + } |
|
91 | 91 | } |
92 | 92 | \ No newline at end of file |
@@ -27,23 +27,23 @@ |
||
27 | 27 | */ |
28 | 28 | |
29 | 29 | if (!class_exists('Error', false)) { |
30 | - // We can't really avoid making this extend Exception in PHP 5. |
|
31 | - class Error extends Exception |
|
32 | - { |
|
30 | + // We can't really avoid making this extend Exception in PHP 5. |
|
31 | + class Error extends Exception |
|
32 | + { |
|
33 | 33 | |
34 | - } |
|
34 | + } |
|
35 | 35 | } |
36 | 36 | |
37 | 37 | if (!class_exists('TypeError', false)) { |
38 | - if (is_subclass_of('Error', 'Exception')) { |
|
39 | - class TypeError extends Error |
|
40 | - { |
|
38 | + if (is_subclass_of('Error', 'Exception')) { |
|
39 | + class TypeError extends Error |
|
40 | + { |
|
41 | 41 | |
42 | - } |
|
43 | - } else { |
|
44 | - class TypeError extends Exception |
|
45 | - { |
|
42 | + } |
|
43 | + } else { |
|
44 | + class TypeError extends Exception |
|
45 | + { |
|
46 | 46 | |
47 | - } |
|
48 | - } |
|
47 | + } |
|
48 | + } |
|
49 | 49 | } |
@@ -30,26 +30,26 @@ discard block |
||
30 | 30 | */ |
31 | 31 | |
32 | 32 | if (!defined('PHP_VERSION_ID')) { |
33 | - // This constant was introduced in PHP 5.2.7 |
|
34 | - $RandomCompatversion = array_map('intval', explode('.', PHP_VERSION)); |
|
35 | - define( |
|
36 | - 'PHP_VERSION_ID', |
|
37 | - $RandomCompatversion[0] * 10000 |
|
38 | - + $RandomCompatversion[1] * 100 |
|
39 | - + $RandomCompatversion[2] |
|
40 | - ); |
|
41 | - $RandomCompatversion = null; |
|
33 | + // This constant was introduced in PHP 5.2.7 |
|
34 | + $RandomCompatversion = array_map('intval', explode('.', PHP_VERSION)); |
|
35 | + define( |
|
36 | + 'PHP_VERSION_ID', |
|
37 | + $RandomCompatversion[0] * 10000 |
|
38 | + + $RandomCompatversion[1] * 100 |
|
39 | + + $RandomCompatversion[2] |
|
40 | + ); |
|
41 | + $RandomCompatversion = null; |
|
42 | 42 | } |
43 | 43 | |
44 | 44 | /** |
45 | 45 | * PHP 7.0.0 and newer have these functions natively. |
46 | 46 | */ |
47 | 47 | if (PHP_VERSION_ID >= 70000) { |
48 | - return; |
|
48 | + return; |
|
49 | 49 | } |
50 | 50 | |
51 | 51 | if (!defined('RANDOM_COMPAT_READ_BUFFER')) { |
52 | - define('RANDOM_COMPAT_READ_BUFFER', 8); |
|
52 | + define('RANDOM_COMPAT_READ_BUFFER', 8); |
|
53 | 53 | } |
54 | 54 | |
55 | 55 | $RandomCompatDIR = dirname(__FILE__); |
@@ -59,167 +59,167 @@ discard block |
||
59 | 59 | require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'error_polyfill.php'; |
60 | 60 | |
61 | 61 | if (!is_callable('random_bytes')) { |
62 | - /** |
|
63 | - * PHP 5.2.0 - 5.6.x way to implement random_bytes() |
|
64 | - * |
|
65 | - * We use conditional statements here to define the function in accordance |
|
66 | - * to the operating environment. It's a micro-optimization. |
|
67 | - * |
|
68 | - * In order of preference: |
|
69 | - * 1. Use libsodium if available. |
|
70 | - * 2. fread() /dev/urandom if available (never on Windows) |
|
71 | - * 3. mcrypt_create_iv($bytes, MCRYPT_DEV_URANDOM) |
|
72 | - * 4. COM('CAPICOM.Utilities.1')->GetRandom() |
|
73 | - * |
|
74 | - * See RATIONALE.md for our reasoning behind this particular order |
|
75 | - */ |
|
76 | - if (extension_loaded('libsodium')) { |
|
77 | - // See random_bytes_libsodium.php |
|
78 | - if (PHP_VERSION_ID >= 50300 && is_callable('\\Sodium\\randombytes_buf')) { |
|
79 | - require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_bytes_libsodium.php'; |
|
80 | - } elseif (method_exists('Sodium', 'randombytes_buf')) { |
|
81 | - require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_bytes_libsodium_legacy.php'; |
|
82 | - } |
|
83 | - } |
|
84 | - |
|
85 | - /** |
|
86 | - * Reading directly from /dev/urandom: |
|
87 | - */ |
|
88 | - if (DIRECTORY_SEPARATOR === '/') { |
|
89 | - // DIRECTORY_SEPARATOR === '/' on Unix-like OSes -- this is a fast |
|
90 | - // way to exclude Windows. |
|
91 | - $RandomCompatUrandom = true; |
|
92 | - $RandomCompat_basedir = ini_get('open_basedir'); |
|
93 | - |
|
94 | - if (!empty($RandomCompat_basedir)) { |
|
95 | - $RandomCompat_open_basedir = explode( |
|
96 | - PATH_SEPARATOR, |
|
97 | - strtolower($RandomCompat_basedir) |
|
98 | - ); |
|
99 | - $RandomCompatUrandom = (array() !== array_intersect( |
|
100 | - array('/dev', '/dev/', '/dev/urandom'), |
|
101 | - $RandomCompat_open_basedir |
|
102 | - )); |
|
103 | - $RandomCompat_open_basedir = null; |
|
104 | - } |
|
105 | - |
|
106 | - if ( |
|
107 | - !is_callable('random_bytes') |
|
108 | - && |
|
109 | - $RandomCompatUrandom |
|
110 | - && |
|
111 | - @is_readable('/dev/urandom') |
|
112 | - ) { |
|
113 | - // Error suppression on is_readable() in case of an open_basedir |
|
114 | - // or safe_mode failure. All we care about is whether or not we |
|
115 | - // can read it at this point. If the PHP environment is going to |
|
116 | - // panic over trying to see if the file can be read in the first |
|
117 | - // place, that is not helpful to us here. |
|
118 | - |
|
119 | - // See random_bytes_dev_urandom.php |
|
120 | - require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_bytes_dev_urandom.php'; |
|
121 | - } |
|
122 | - // Unset variables after use |
|
123 | - $RandomCompat_basedir = null; |
|
124 | - } else { |
|
125 | - $RandomCompatUrandom = false; |
|
126 | - } |
|
127 | - |
|
128 | - /** |
|
129 | - * mcrypt_create_iv() |
|
130 | - * |
|
131 | - * We only want to use mcypt_create_iv() if: |
|
132 | - * |
|
133 | - * - random_bytes() hasn't already been defined |
|
134 | - * - the mcrypt extensions is loaded |
|
135 | - * - One of these two conditions is true: |
|
136 | - * - We're on Windows (DIRECTORY_SEPARATOR !== '/') |
|
137 | - * - We're not on Windows and /dev/urandom is readabale |
|
138 | - * (i.e. we're not in a chroot jail) |
|
139 | - * - Special case: |
|
140 | - * - If we're not on Windows, but the PHP version is between |
|
141 | - * 5.6.10 and 5.6.12, we don't want to use mcrypt. It will |
|
142 | - * hang indefinitely. This is bad. |
|
143 | - * - If we're on Windows, we want to use PHP >= 5.3.7 or else |
|
144 | - * we get insufficient entropy errors. |
|
145 | - */ |
|
146 | - if ( |
|
147 | - !is_callable('random_bytes') |
|
148 | - && |
|
149 | - // Windows on PHP < 5.3.7 is broken, but non-Windows is not known to be. |
|
150 | - (DIRECTORY_SEPARATOR === '/' || PHP_VERSION_ID >= 50307) |
|
151 | - && |
|
152 | - // Prevent this code from hanging indefinitely on non-Windows; |
|
153 | - // see https://bugs.php.net/bug.php?id=69833 |
|
154 | - ( |
|
155 | - DIRECTORY_SEPARATOR !== '/' || |
|
156 | - (PHP_VERSION_ID <= 50609 || PHP_VERSION_ID >= 50613) |
|
157 | - ) |
|
158 | - && |
|
159 | - extension_loaded('mcrypt') |
|
160 | - ) { |
|
161 | - // See random_bytes_mcrypt.php |
|
162 | - require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_bytes_mcrypt.php'; |
|
163 | - } |
|
164 | - $RandomCompatUrandom = null; |
|
165 | - |
|
166 | - /** |
|
167 | - * This is a Windows-specific fallback, for when the mcrypt extension |
|
168 | - * isn't loaded. |
|
169 | - */ |
|
170 | - if ( |
|
171 | - !is_callable('random_bytes') |
|
172 | - && |
|
173 | - extension_loaded('com_dotnet') |
|
174 | - && |
|
175 | - class_exists('COM') |
|
176 | - ) { |
|
177 | - $RandomCompat_disabled_classes = preg_split( |
|
178 | - '#\s*,\s*#', |
|
179 | - strtolower(ini_get('disable_classes')) |
|
180 | - ); |
|
181 | - |
|
182 | - if (!in_array('com', $RandomCompat_disabled_classes)) { |
|
183 | - try { |
|
184 | - $RandomCompatCOMtest = new COM('CAPICOM.Utilities.1'); |
|
185 | - if (method_exists($RandomCompatCOMtest, 'GetRandom')) { |
|
186 | - // See random_bytes_com_dotnet.php |
|
187 | - require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_bytes_com_dotnet.php'; |
|
188 | - } |
|
189 | - } catch (com_exception $e) { |
|
190 | - // Don't try to use it. |
|
191 | - } |
|
192 | - } |
|
193 | - $RandomCompat_disabled_classes = null; |
|
194 | - $RandomCompatCOMtest = null; |
|
195 | - } |
|
196 | - |
|
197 | - /** |
|
198 | - * throw new Exception |
|
199 | - */ |
|
200 | - if (!is_callable('random_bytes')) { |
|
201 | - /** |
|
202 | - * We don't have any more options, so let's throw an exception right now |
|
203 | - * and hope the developer won't let it fail silently. |
|
204 | - * |
|
205 | - * @param mixed $length |
|
206 | - * @psalm-suppress InvalidReturnType |
|
207 | - * @throws Exception |
|
208 | - * @return string |
|
209 | - */ |
|
210 | - function random_bytes($length) |
|
211 | - { |
|
212 | - unset($length); // Suppress "variable not used" warnings. |
|
213 | - throw new Exception( |
|
214 | - 'There is no suitable CSPRNG installed on your system' |
|
215 | - ); |
|
216 | - return ''; |
|
217 | - } |
|
218 | - } |
|
62 | + /** |
|
63 | + * PHP 5.2.0 - 5.6.x way to implement random_bytes() |
|
64 | + * |
|
65 | + * We use conditional statements here to define the function in accordance |
|
66 | + * to the operating environment. It's a micro-optimization. |
|
67 | + * |
|
68 | + * In order of preference: |
|
69 | + * 1. Use libsodium if available. |
|
70 | + * 2. fread() /dev/urandom if available (never on Windows) |
|
71 | + * 3. mcrypt_create_iv($bytes, MCRYPT_DEV_URANDOM) |
|
72 | + * 4. COM('CAPICOM.Utilities.1')->GetRandom() |
|
73 | + * |
|
74 | + * See RATIONALE.md for our reasoning behind this particular order |
|
75 | + */ |
|
76 | + if (extension_loaded('libsodium')) { |
|
77 | + // See random_bytes_libsodium.php |
|
78 | + if (PHP_VERSION_ID >= 50300 && is_callable('\\Sodium\\randombytes_buf')) { |
|
79 | + require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_bytes_libsodium.php'; |
|
80 | + } elseif (method_exists('Sodium', 'randombytes_buf')) { |
|
81 | + require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_bytes_libsodium_legacy.php'; |
|
82 | + } |
|
83 | + } |
|
84 | + |
|
85 | + /** |
|
86 | + * Reading directly from /dev/urandom: |
|
87 | + */ |
|
88 | + if (DIRECTORY_SEPARATOR === '/') { |
|
89 | + // DIRECTORY_SEPARATOR === '/' on Unix-like OSes -- this is a fast |
|
90 | + // way to exclude Windows. |
|
91 | + $RandomCompatUrandom = true; |
|
92 | + $RandomCompat_basedir = ini_get('open_basedir'); |
|
93 | + |
|
94 | + if (!empty($RandomCompat_basedir)) { |
|
95 | + $RandomCompat_open_basedir = explode( |
|
96 | + PATH_SEPARATOR, |
|
97 | + strtolower($RandomCompat_basedir) |
|
98 | + ); |
|
99 | + $RandomCompatUrandom = (array() !== array_intersect( |
|
100 | + array('/dev', '/dev/', '/dev/urandom'), |
|
101 | + $RandomCompat_open_basedir |
|
102 | + )); |
|
103 | + $RandomCompat_open_basedir = null; |
|
104 | + } |
|
105 | + |
|
106 | + if ( |
|
107 | + !is_callable('random_bytes') |
|
108 | + && |
|
109 | + $RandomCompatUrandom |
|
110 | + && |
|
111 | + @is_readable('/dev/urandom') |
|
112 | + ) { |
|
113 | + // Error suppression on is_readable() in case of an open_basedir |
|
114 | + // or safe_mode failure. All we care about is whether or not we |
|
115 | + // can read it at this point. If the PHP environment is going to |
|
116 | + // panic over trying to see if the file can be read in the first |
|
117 | + // place, that is not helpful to us here. |
|
118 | + |
|
119 | + // See random_bytes_dev_urandom.php |
|
120 | + require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_bytes_dev_urandom.php'; |
|
121 | + } |
|
122 | + // Unset variables after use |
|
123 | + $RandomCompat_basedir = null; |
|
124 | + } else { |
|
125 | + $RandomCompatUrandom = false; |
|
126 | + } |
|
127 | + |
|
128 | + /** |
|
129 | + * mcrypt_create_iv() |
|
130 | + * |
|
131 | + * We only want to use mcypt_create_iv() if: |
|
132 | + * |
|
133 | + * - random_bytes() hasn't already been defined |
|
134 | + * - the mcrypt extensions is loaded |
|
135 | + * - One of these two conditions is true: |
|
136 | + * - We're on Windows (DIRECTORY_SEPARATOR !== '/') |
|
137 | + * - We're not on Windows and /dev/urandom is readabale |
|
138 | + * (i.e. we're not in a chroot jail) |
|
139 | + * - Special case: |
|
140 | + * - If we're not on Windows, but the PHP version is between |
|
141 | + * 5.6.10 and 5.6.12, we don't want to use mcrypt. It will |
|
142 | + * hang indefinitely. This is bad. |
|
143 | + * - If we're on Windows, we want to use PHP >= 5.3.7 or else |
|
144 | + * we get insufficient entropy errors. |
|
145 | + */ |
|
146 | + if ( |
|
147 | + !is_callable('random_bytes') |
|
148 | + && |
|
149 | + // Windows on PHP < 5.3.7 is broken, but non-Windows is not known to be. |
|
150 | + (DIRECTORY_SEPARATOR === '/' || PHP_VERSION_ID >= 50307) |
|
151 | + && |
|
152 | + // Prevent this code from hanging indefinitely on non-Windows; |
|
153 | + // see https://bugs.php.net/bug.php?id=69833 |
|
154 | + ( |
|
155 | + DIRECTORY_SEPARATOR !== '/' || |
|
156 | + (PHP_VERSION_ID <= 50609 || PHP_VERSION_ID >= 50613) |
|
157 | + ) |
|
158 | + && |
|
159 | + extension_loaded('mcrypt') |
|
160 | + ) { |
|
161 | + // See random_bytes_mcrypt.php |
|
162 | + require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_bytes_mcrypt.php'; |
|
163 | + } |
|
164 | + $RandomCompatUrandom = null; |
|
165 | + |
|
166 | + /** |
|
167 | + * This is a Windows-specific fallback, for when the mcrypt extension |
|
168 | + * isn't loaded. |
|
169 | + */ |
|
170 | + if ( |
|
171 | + !is_callable('random_bytes') |
|
172 | + && |
|
173 | + extension_loaded('com_dotnet') |
|
174 | + && |
|
175 | + class_exists('COM') |
|
176 | + ) { |
|
177 | + $RandomCompat_disabled_classes = preg_split( |
|
178 | + '#\s*,\s*#', |
|
179 | + strtolower(ini_get('disable_classes')) |
|
180 | + ); |
|
181 | + |
|
182 | + if (!in_array('com', $RandomCompat_disabled_classes)) { |
|
183 | + try { |
|
184 | + $RandomCompatCOMtest = new COM('CAPICOM.Utilities.1'); |
|
185 | + if (method_exists($RandomCompatCOMtest, 'GetRandom')) { |
|
186 | + // See random_bytes_com_dotnet.php |
|
187 | + require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_bytes_com_dotnet.php'; |
|
188 | + } |
|
189 | + } catch (com_exception $e) { |
|
190 | + // Don't try to use it. |
|
191 | + } |
|
192 | + } |
|
193 | + $RandomCompat_disabled_classes = null; |
|
194 | + $RandomCompatCOMtest = null; |
|
195 | + } |
|
196 | + |
|
197 | + /** |
|
198 | + * throw new Exception |
|
199 | + */ |
|
200 | + if (!is_callable('random_bytes')) { |
|
201 | + /** |
|
202 | + * We don't have any more options, so let's throw an exception right now |
|
203 | + * and hope the developer won't let it fail silently. |
|
204 | + * |
|
205 | + * @param mixed $length |
|
206 | + * @psalm-suppress InvalidReturnType |
|
207 | + * @throws Exception |
|
208 | + * @return string |
|
209 | + */ |
|
210 | + function random_bytes($length) |
|
211 | + { |
|
212 | + unset($length); // Suppress "variable not used" warnings. |
|
213 | + throw new Exception( |
|
214 | + 'There is no suitable CSPRNG installed on your system' |
|
215 | + ); |
|
216 | + return ''; |
|
217 | + } |
|
218 | + } |
|
219 | 219 | } |
220 | 220 | |
221 | 221 | if (!is_callable('random_int')) { |
222 | - require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_int.php'; |
|
222 | + require_once $RandomCompatDIR . DIRECTORY_SEPARATOR . 'random_int.php'; |
|
223 | 223 | } |
224 | 224 | |
225 | 225 | $RandomCompatDIR = null; |
@@ -27,67 +27,67 @@ |
||
27 | 27 | */ |
28 | 28 | |
29 | 29 | if (!is_callable('random_bytes')) { |
30 | - /** |
|
31 | - * If the libsodium PHP extension is loaded, we'll use it above any other |
|
32 | - * solution. |
|
33 | - * |
|
34 | - * libsodium-php project: |
|
35 | - * @ref https://github.com/jedisct1/libsodium-php |
|
36 | - * |
|
37 | - * @param int $bytes |
|
38 | - * |
|
39 | - * @throws Exception |
|
40 | - * |
|
41 | - * @return string |
|
42 | - */ |
|
43 | - function random_bytes($bytes) |
|
44 | - { |
|
45 | - try { |
|
46 | - /** @var int $bytes */ |
|
47 | - $bytes = RandomCompat_intval($bytes); |
|
48 | - } catch (TypeError $ex) { |
|
49 | - throw new TypeError( |
|
50 | - 'random_bytes(): $bytes must be an integer' |
|
51 | - ); |
|
52 | - } |
|
30 | + /** |
|
31 | + * If the libsodium PHP extension is loaded, we'll use it above any other |
|
32 | + * solution. |
|
33 | + * |
|
34 | + * libsodium-php project: |
|
35 | + * @ref https://github.com/jedisct1/libsodium-php |
|
36 | + * |
|
37 | + * @param int $bytes |
|
38 | + * |
|
39 | + * @throws Exception |
|
40 | + * |
|
41 | + * @return string |
|
42 | + */ |
|
43 | + function random_bytes($bytes) |
|
44 | + { |
|
45 | + try { |
|
46 | + /** @var int $bytes */ |
|
47 | + $bytes = RandomCompat_intval($bytes); |
|
48 | + } catch (TypeError $ex) { |
|
49 | + throw new TypeError( |
|
50 | + 'random_bytes(): $bytes must be an integer' |
|
51 | + ); |
|
52 | + } |
|
53 | 53 | |
54 | - if ($bytes < 1) { |
|
55 | - throw new Error( |
|
56 | - 'Length must be greater than 0' |
|
57 | - ); |
|
58 | - } |
|
54 | + if ($bytes < 1) { |
|
55 | + throw new Error( |
|
56 | + 'Length must be greater than 0' |
|
57 | + ); |
|
58 | + } |
|
59 | 59 | |
60 | - /** |
|
61 | - * @var string |
|
62 | - */ |
|
63 | - $buf = ''; |
|
60 | + /** |
|
61 | + * @var string |
|
62 | + */ |
|
63 | + $buf = ''; |
|
64 | 64 | |
65 | - /** |
|
66 | - * \Sodium\randombytes_buf() doesn't allow more than 2147483647 bytes to be |
|
67 | - * generated in one invocation. |
|
68 | - */ |
|
69 | - if ($bytes > 2147483647) { |
|
70 | - for ($i = 0; $i < $bytes; $i += 1073741824) { |
|
71 | - $n = ($bytes - $i) > 1073741824 |
|
72 | - ? 1073741824 |
|
73 | - : $bytes - $i; |
|
74 | - $buf .= Sodium::randombytes_buf((int) $n); |
|
75 | - } |
|
76 | - } else { |
|
77 | - $buf .= Sodium::randombytes_buf((int) $bytes); |
|
78 | - } |
|
65 | + /** |
|
66 | + * \Sodium\randombytes_buf() doesn't allow more than 2147483647 bytes to be |
|
67 | + * generated in one invocation. |
|
68 | + */ |
|
69 | + if ($bytes > 2147483647) { |
|
70 | + for ($i = 0; $i < $bytes; $i += 1073741824) { |
|
71 | + $n = ($bytes - $i) > 1073741824 |
|
72 | + ? 1073741824 |
|
73 | + : $bytes - $i; |
|
74 | + $buf .= Sodium::randombytes_buf((int) $n); |
|
75 | + } |
|
76 | + } else { |
|
77 | + $buf .= Sodium::randombytes_buf((int) $bytes); |
|
78 | + } |
|
79 | 79 | |
80 | - if (is_string($buf)) { |
|
81 | - if (RandomCompat_strlen($buf) === $bytes) { |
|
82 | - return $buf; |
|
83 | - } |
|
84 | - } |
|
80 | + if (is_string($buf)) { |
|
81 | + if (RandomCompat_strlen($buf) === $bytes) { |
|
82 | + return $buf; |
|
83 | + } |
|
84 | + } |
|
85 | 85 | |
86 | - /** |
|
87 | - * If we reach here, PHP has failed us. |
|
88 | - */ |
|
89 | - throw new Exception( |
|
90 | - 'Could not gather sufficient random data' |
|
91 | - ); |
|
92 | - } |
|
86 | + /** |
|
87 | + * If we reach here, PHP has failed us. |
|
88 | + */ |
|
89 | + throw new Exception( |
|
90 | + 'Could not gather sufficient random data' |
|
91 | + ); |
|
92 | + } |
|
93 | 93 | } |