NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #124 most downloaded on Packagist
PHP 5.x polyfill for random_bytes() and random_int() from PHP 7
Last release 5 years ago
no release in 18 months
Release timing varies
gaps range from 2 weeks to 1.8 years
Most releases are documented
notes for 52 of 59 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
59 releases · first in 2015
Version 9.99.100 (2020-10-15)
Version 9.99.100 (2020-10-15)
Nothing published for this version
Fix #175 - Fix CAPICOM usage on Windows
One column per quarter.
Switched from Travis CI to Github Actions
Adds support for PHP 8 projects in Composer constraint
If /dev/urandom cannot be read on Unix-based operating systems, a Exception with a specific error message will be thrown.
/dev/urandom cannot be read on Unix-based operating systems,Version 2.0.16 failed Psalm checks on PHP v5.6 with Psalm v1. We could not reproduce this failure locally, so we've suppressed the MissingReturnType c
MissingReturnType check (that is to say, demoted it to "info").Fixed type-checking consistencies that forced us to use Psalm in non-strict mode (i.e. totallyTyped="false" ).
totallyTyped="false").v9.99.99 and it's causing stuff to break, see this section of the README for the solution to your problem.psalm.xml file with explanations for why each assertion is suppressed.A reported, but difficult to reproduce, problem with file inclusion on some Windows machines was fixed by replacing / with DIRECTORY_SEPARATOR . For m
/ with DIRECTORY_SEPARATOR.Updated README with better instructions, including new information about the v9.99.99 tag.
v9.99.99 tag.Ensure the docblocks are consistent to aid static analysis efforts in other libraries; see https://github.com/paragonie/random_compat/commit/cbe0b11b7
polyfill keyword to composer.jsonMinor docblock issue that's breaking Psalm downstream.
Re-issuing a PHP Archive to attempt to address an issue with the Phar provided. See #134.
Mcrypt can now be used on PHP < 5.3.7 if you're not on Windows.
* More Psalm integration fixes.
Prevent function already declared error for random_int() caused by misusing the library (really you should only ever include lib/random.php and never
random_int() caused by misusing
the library (really you should only ever include lib/random.php and never any
of the other files). See #125.Nothing published for this version
Just updates to psalm.xml to silence false positives.
Run random_compat through the static analysis tool, psalm, as part of our continuous integration process.
Don't unnecessarily prevent mcrypt_create_iv() from being used. See #111.
mcrypt_create_iv() from being used.
See #111.Updated lib/error_polyfill.php to resolve corner cases.
lib/error_polyfill.php to resolve corner cases.Added a consistency check (discovered by Taylor Hornby in his PHP encryption library). It wasn't likely causing any trouble for us.
Added a consistency check (discovered by Taylor Hornby in his PHP encryption library). It wasn't likely causing any trouble for us.
Update comment in random.php
Update comment in random.php
Due to downstream errors, the OpenSSL removal now belongs in version 2.0.0.
Due to downstream errors, the OpenSSL removal now belongs in version 2.0.0.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add more possible values to open_basedir check.
open_basedir check.Removed openssl_random_pseudo_bytes() entirely. If you are using random_compat in PHP on a Unix-like OS but cannot access /dev/urandom, version 1.3+ w
Removed openssl_random_pseudo_bytes() entirely. If you are using
random_compat in PHP on a Unix-like OS but cannot access
/dev/urandom, version 1.3+ will throw an Exception. If you want to
trust OpenSSL, feel free to write your own fallback code. e.g.
try {
$bytes = random_bytes(32);
} catch (Exception $ex) {
$strong = false;
$bytes = openssl_random_pseudo_bytes(32, $strong);
if (!$strong) {
throw $ex;
}
}
Nothing published for this version
To prevent applications from hanging, if /dev/urandom is not accessible to PHP, skip mcrypt (which just fails before giving OpenSSL a chance and was m
/dev/urandom is not
accessible to PHP, skip mcrypt (which just fails before giving OpenSSL
a chance and was morally equivalent to not offering OpenSSL at all).PHP 5.6.10 - 5.6.12 will hang when mcrypt is used on Unix-based operating systems (PHP bug 69833). If you are running one of these versions, please up
/dev/urandom is
readable) otherwise you're relying on OpenSSL.Whitespace and other cosmetic changes
Whitespace and other cosmetic changes
Added a changelog.
We now ship with a command line utility to build a PHP Archive from the command line.
Every time we publish a new release, we will also upload a .phar to Github. Our public key is signed by our GPG key.
Eliminate open_basedir warnings by detecting this configuration setting. (Thanks @oucil for reporting this.)
open_basedir warnings by detecting this configuration setting.
(Thanks @oucil for reporting this.)MCRYPT_CREATE_IV constant, I
meant to write MCRYPT_DEV_URANDOM)Prevent fatal errors on platforms with older versions of libsodium.
Prevent fatal errors on platforms with older versions of libsodium.
Thanks @narfbg for critiquing the previous patch and suggesting a fix.
Thanks @narfbg for critiquing the previous patch and suggesting a fix.
The test for COM in disabled_classes is now case-insensitive.
The test for COM in disabled_classes is now case-insensitive.
Don't instantiate COM if it's a disabled class. Removes the E_WARNING on Windows.
Don't instantiate COM if it's a disabled class. Removes the E_WARNING on Windows.
Fix a performance issue with /dev/urandom buffering.
Fix a performance issue with /dev/urandom buffering.
Fix performance issues with ancient versions of PHP on Windows, but dropped support for PHP < 5.4.1 without mcrypt on Windows 7+ in the process. Since
Fix performance issues with ancient versions of PHP on Windows, but dropped support for PHP < 5.4.1 without mcrypt on Windows 7+ in the process. Since this is a BC break, semver dictates a minor version bump.
Avoid a performance killer with OpenSSL on Windows PHP 5.3.0 - 5.3.3 that was affecting WordPress users.
$var = null instead of unset($var) to avoid triggering the garbage
collector and slowing things down.There is an outstanding issue mcrypt_create_iv() and PHP 7's random_bytes() on Windows reported by @nicolas-grekas caused by proc_open() and environme
There is an outstanding issue mcrypt_create_iv() and PHP 7's random_bytes()
on Windows reported by @nicolas-grekas caused by proc_open() and environment
variable handling (discovered by Appveyor when developing Symfony).
Since the break is consistent, it's not our responsibility to fix it, but we
should fail the same way PHP 7 will (i.e. throw an Exception rather than raise
an error and then throw an Exception).
Fix usability issues with Windows (new COM('CAPICOM.Utilities.1') is not always available).
new COM('CAPICOM.Utilities.1') is not
always available).phpunit.sh each in the
tests directory.Several large integer handling bugfixes were contributed by @oittaa.
Several large integer handling bugfixes were contributed by @oittaa.
Don't let the version number fool you, this was a pretty significant change.
Don't let the version number fool you, this was a pretty significant change.
getrandom(2) support without having to expose the
syscall interface in PHP-land./dev/urandom. Now it will still do
so if you can.One change that we discussed was making random_bytes() and random_int()
strict typed; meaning you could only pass integers to either function. While
most veteran programmers are probably only doing this already (we strongly
encourage it), it wouldn't be consistent with how these functions behave in PHP
7. Please use these functions responsibly.
We've had even more of the PHP community involved in this release; the contributors list has been updated. If I forgot anybody, I promise you it's not because your contributions (either code or ideas) aren't valued, it's because I'm a bit overloaded with information at the moment. Please let me know immediately and I will correct my oversight.
Thanks everyone for helping make random_compat better.
Got rid of the methods in the Throwable interface, which was causing problems on PHP 5.2. While we would normally not care about 5.2 (since 5.4 and ea
Got rid of the methods in the Throwable interface, which was causing problems
on PHP 5.2. While we would normally not care about 5.2 (since 5.4 and earlier are EOL'd),
we do want to encourage widespread adoption (e.g. Wordpress).
Removed redundant if() checks, since lib/random.php is the entrypoint people should use.
Removed redundant if() checks, since lib/random.php is the entrypoint people
should use.
This release contains bug fixes contributed by the community.
This release contains bug fixes contributed by the community.
Although none of these bugs were outright security-affecting, updating ASAP is still strongly encouraged.
Less strict input validation on random_int() parameters. PHP 7's random_int() accepts strings and floats that look like numbers, so we should too.
Less strict input validation on random_int() parameters. PHP 7's random_int()
accepts strings and floats that look like numbers, so we should too.
Thanks @dd32 for correcting this oversight.
Instead of throwing an Exception immediately on insecure platforms, only do so when random_bytes() is invoked.
Instead of throwing an Exception immediately on insecure platforms, only do so
when random_bytes() is invoked.
Our API is now stable and forward-compatible with the CSPRNG features in PHP 7 (as of 7.0.0 RC3).
Our API is now stable and forward-compatible with the CSPRNG features in PHP 7 (as of 7.0.0 RC3).
A lot of great people have contributed their time and expertise to make this compatibility library possible. That this library has reached a stable release is more a reflection on the community than it is on PIE.
We are confident that random_compat will serve as the simplest and most secure CSPRNG interface available for PHP5 projects.
An attempt to achieve compatibility with Error/TypeError in the RFC.
An attempt to achieve compatibility with Error/TypeError in the RFC.
This should be identical to 1.0.0 sans any last-minute changes or performance enhancements.
Validate that /dev/urandom is a character device
/dev/urandom is a character device
/dev/arandom which is an old OpenBSD feature, thanks @jedisct1filetype() check, thanks @jedisct1Add logic to verify that /dev/arandom and /dev/urandom are actually devices.
/dev/arandom and /dev/urandom are actually devices.Unless the Exceptions change to PHP 7 fails, this should be the last pre-release version. If need be, we'll make one more pre-release version with com
Unless the Exceptions change to PHP 7 fails, this should be the last pre-release version. If need be, we'll make one more pre-release version with compatible behavior.
Changes since 0.9.2:
/dev/arandom and /dev/urandom over mcrypt.
@oittaa removed the -1 and +1 juggling on $range calculations for random_int()Consolidated $range > PHP_INT_MAX logic with $range <= PHP_INT_MAX (thanks @oittaa and @CodesInChaos)
$range > PHP_INT_MAX logic with $range <= PHP_INT_MAX (thanks
@oittaa and @CodesInChaos)tests/phpunit.sh now also runs the tests with mbstring.func_overload and
open_basedirReturn random values on integer ranges > PHP_INT_MAX (thanks @CodesInChaos)
PHP_INT_MAX (thanks @CodesInChaos)mcrypt_create_iv() with MCRYPT_DEV_URANDOM/dev/arandom/dev/urandomopenssl_random_pseudo_bytes()This should be a sane polyfill for PHP 7's random_bytes() and random_int(). We hesitate to call it production ready until it has received sufficient t
This should be a sane polyfill for PHP 7's random_bytes() and random_int().
We hesitate to call it production ready until it has received sufficient third
party review.
Your coding agent can read these notes before it upgrades. Set up the MCP server →