Skip to content

Fix RNG reuse in ENIP generateId() - #108

Open
mmguero wants to merge 1 commit into
cisagov:mainfrom
mmguero-dev:main
Open

Fix RNG reuse in ENIP generateId()#108
mmguero wants to merge 1 commit into
cisagov:mainfrom
mmguero-dev:main

Conversation

@mmguero

@mmguero mmguero commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Hoist random_device/mt19937/uniform_int_distribution out of the per-byte loop into function-static locals, constructed once instead of on every iteration. Fixes both a perf issue (repeated entropy syscalls) and a correctness risk: random_device may fall back to a deterministic sequence on some platforms, which combined with per-iteration re-seeding could produce identical bytes across the whole ID. Safe as static (not thread_local) since Zeek's packet analysis path is single-threaded.

Hoist random_device/mt19937/uniform_int_distribution out of the
per-byte loop into function-static locals, constructed once instead
of on every iteration. Fixes both a perf issue (repeated entropy
syscalls) and a correctness risk: random_device may fall back to a
deterministic sequence on some platforms, which combined with
per-iteration re-seeding could produce identical bytes across the
whole ID. Safe as static (not thread_local) since Zeek's packet
analysis path is single-threaded.

Signed-off-by: Seth Grover <seth.d.grover@gmail.com>
@mmguero
mmguero marked this pull request as ready for review July 16, 2026 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant