Index | Thread | Search

From:
Biarder <mss091204.1@gmail.com>
Subject:
Re: ksh(1), use arc4random_uniform(3) to calculate $RANDOM
To:
Theo de Raadt <deraadt@openbsd.org>
Cc:
tech@openbsd.org
Date:
Sat, 23 May 2026 08:14:25 +0700

Download raw body.

Thread
No, I didn't mean to. I'm so sorry.

I read the manual as you advised, and I realized why I was wrong, and I
wanted to thank you for letting me study and develop the code's behavior to
make it work deterministically.

I'm so sorry.

2026년 5월 23일 (토) 오전 7:02, Theo de Raadt <deraadt@openbsd.org>님이 작성:

> Are you making a claim that we can change this?
>
> > localhost$ RANDOM=1; echo
> >     $(echo $RANDOM $RANDOM $RANDOM) $(echo $RANDOM $RANDOM $RANDOM)
> > 32422 12519 25748 12519 25748 6973
> >
> > The first child starts with 32422. This is the result of RANDOM=1.
> > The second child starts with 12519. Executing the child and
> > change_random() calls the rand() to advance the seed. Thus 12519
> > advances from 32442, which is also in the second random number
> > of the first child.
> >
> > "Ensure next child gets a (slightly) different $RANDOM sequence."
> > As the comment explains, the next child receives a different $RANDOM
> > seed than before, which advances one seed only one step forward.
> >
> > Thank you for your review, I learned about OpenBSD's implementation
> > due to your help.
> >
> > 2026년 5월 22일 (금) 오후 10:21, Theo de Raadt <deraadt@openbsd.org>님이 작성:
> > >
> > > Biarder <mss091204.1@gmail.com> wrote:
> > >
> > > > Currently, ksh(1) uses rand(3) and modular arithmetic to calculate
> > > > $RANDOM.  However, OpenBSD recommend using arc4random_uniform(3)
> > > > to calculate a uniform random integer because rand function is
> > > > predictable and also has modular bias when modulo operation is
> > > > performed.
> > >
> > > Your change is incorrect.  There are situations when ksh randomness
> > > must follow the rand() method.
> > >
> > > This is handled by not using arcrandom(), but by using the rand()
> > > which _is_ arc4random() behind the scenes unless srand_deterministic()
> > > is called.  And srand_deterministic() is called, in those
> circumstances,
> > > to satisfy that requirement.
> > >
> > > It is in the manual page.
> > >
> > >      RANDOM     A random number generator.  Every time RANDOM is
> referenced,
> > >                 it is assigned the next random number in the range
> 0-32767.
> > >                 By default, arc4random(3) is used to produce values.
> If the
> > >                 variable RANDOM is assigned a value, the value is used
> as the
> > >                 seed to srand_deterministic(3) and subsequent
> references of
> > >                 RANDOM produce a predictable sequence.
> > >
> > > This work was done in 2004.  When making changes, please look at the
> history
> > > of the code you are touching.  In this case 'grep arc4random' would
> have found
> > > you this reference, the commit message, and this text above.  If you
> had
> > > done 'man rand', you would have learned the rest of it.
> > >
> > >
>