Download raw body.
ksh(1), use arc4random_uniform(3) to calculate $RANDOM
I found out what the change_random() function was doing, and I realized how stupid my patch was, so I sent you an email to thank those who helped me realize it. 2026년 5월 23일 (토) 오전 7:07, Theo de Raadt <deraadt@openbsd.org>님이 작성: > This is not "about OpenBSD's implementation" > > The ksy specification does not say what happens if RANDOM is > not assigned. We've changed that behaviour, which makes most > programs safe. > > We did this carefully, more than ten years ago, and have watched > for fallout. > > But programs which set RAMDOM may exist, and the behaviour in > that case is somewhat specified. We did not break those programs. > > That is why our change was careful. > > Your proposal affected all programs. You provide no study, and > no justification. > > To provide clarity to everyone, I recommend you reply that your > suggestion was wrong. > > > localhost$ RANDOM=1; echo > > $(echo $RANDOM $RANDOM $RANDOM) $(echo $RANDOM $RANDOM $RANDOM) > > 32422 12519 25748 12519 25748 6973 > > > > The first child starts with 32422. This is the result of RANDOM=1. > > The second child starts with 12519. Executing the child and > > change_random() calls the rand() to advance the seed. Thus 12519 > > advances from 32442, which is also in the second random number > > of the first child. > > > > "Ensure next child gets a (slightly) different $RANDOM sequence." > > As the comment explains, the next child receives a different $RANDOM > > seed than before, which advances one seed only one step forward. > > > > Thank you for your review, I learned about OpenBSD's implementation > > due to your help. > > > > 2026년 5월 22일 (금) 오후 10:21, Theo de Raadt <deraadt@openbsd.org>님이 작성: > > > > > > Biarder <mss091204.1@gmail.com> wrote: > > > > > > > Currently, ksh(1) uses rand(3) and modular arithmetic to calculate > > > > $RANDOM. However, OpenBSD recommend using arc4random_uniform(3) > > > > to calculate a uniform random integer because rand function is > > > > predictable and also has modular bias when modulo operation is > > > > performed. > > > > > > Your change is incorrect. There are situations when ksh randomness > > > must follow the rand() method. > > > > > > This is handled by not using arcrandom(), but by using the rand() > > > which _is_ arc4random() behind the scenes unless srand_deterministic() > > > is called. And srand_deterministic() is called, in those > circumstances, > > > to satisfy that requirement. > > > > > > It is in the manual page. > > > > > > RANDOM A random number generator. Every time RANDOM is > referenced, > > > it is assigned the next random number in the range > 0-32767. > > > By default, arc4random(3) is used to produce values. > If the > > > variable RANDOM is assigned a value, the value is used > as the > > > seed to srand_deterministic(3) and subsequent > references of > > > RANDOM produce a predictable sequence. > > > > > > This work was done in 2004. When making changes, please look at the > history > > > of the code you are touching. In this case 'grep arc4random' would > have found > > > you this reference, the commit message, and this text above. If you > had > > > done 'man rand', you would have learned the rest of it. > > > > > > >
ksh(1), use arc4random_uniform(3) to calculate $RANDOM