mirror of
https://github.com/Cockatrice/Cockatrice.git
synced 2026-09-21 09:05:10 -07:00
Some checks are pending
CodeQL / Analyze (cpp) (push) Waiting to run
CodeQL / Analyze (actions) (push) Waiting to run
Build Desktop / Configure (push) Waiting to run
Build Desktop / Debian 13 (push) Blocked by required conditions
Build Desktop / Debian 12 (push) Blocked by required conditions
Build Desktop / Fedora 44 (push) Blocked by required conditions
Build Desktop / Fedora 43 (push) Blocked by required conditions
Build Desktop / Servatrice_Debian 12 (push) Blocked by required conditions
Build Desktop / Ubuntu 26.04 (push) Blocked by required conditions
Build Desktop / Ubuntu 24.04 (push) Blocked by required conditions
Build Desktop / Arch (push) Blocked by required conditions
Build Desktop / macOS 13 Intel (push) Blocked by required conditions
Build Desktop / macOS 14 (push) Blocked by required conditions
Build Desktop / macOS 15 (push) Blocked by required conditions
Build Desktop / macOS 26 Debug (push) Blocked by required conditions
Build Desktop / Windows 10 (push) Blocked by required conditions
Build Docker / Servatrice (arm) (push) Waiting to run
Build Docker / Servatrice (x86) (push) Waiting to run
Build Docker / Publish multi-platform Servatrice image (push) Blocked by required conditions
* [Security] Use a CSPRNG for salts, tokens, and RNG seeding Password salts and activation tokens were generated with the global SFMT RNG, which was seeded from a 32-bit timestamp, making registration salts and activation tokens predictable. The game RNG used the same timestamp seed across restarts. Add CryptoUtil backed by OpenSSL RAND_bytes and use it for salt/token generation and to seed RNG_SFMT with a 64-bit CSPRNG value in both the client and server. Link libcockatrice_utility against OpenSSL::Crypto. Took 30 seconds Took 25 minutes * Lint. Took 4 minutes Took 36 seconds --------- Co-authored-by: Lukas Brübach <Bruebach.Lukas@bdosecurity.de>
43 lines
1.4 KiB
C++
43 lines
1.4 KiB
C++
#ifndef RNG_SFMT_H
|
|
#define RNG_SFMT_H
|
|
|
|
#include "rng_abstract.h"
|
|
#include "sfmt/SFMT.h"
|
|
|
|
#include <QMutex>
|
|
#include <climits>
|
|
|
|
/**
|
|
* This class encapsulates a state of the art PRNG and can be used
|
|
* to return uniformly distributed integer random numbers from a range [min, max].
|
|
* Though technically possible, min must be >= 0 and max should always be > 0.
|
|
* If max < 0 and min == 0 it is assumed that rand() % -max is wanted and the result will
|
|
* be -rand(0, -max).
|
|
* This is the only exception to the rule that !(min > max) and is actually unused in
|
|
* Cockatrice.
|
|
*
|
|
* Technical details:
|
|
* The RNG uses the SIMD-oriented Fast Mersenne Twister code v1.4.1 from
|
|
* http://www.math.sci.hiroshima-u.ac.jp/~%20m-mat/MT/SFMT/index.html
|
|
* The SFMT RNG creates unsigned int 64bit pseudo random numbers.
|
|
*
|
|
* These are mapped to values from the interval [min, max] without bias by using Knuth's
|
|
* "Algorithm S (Selection sampling technique)" from "The Art of Computer Programming 3rd
|
|
* Edition Volume 2 / Seminumerical Algorithms".
|
|
*/
|
|
|
|
class RNG_SFMT : public RNG_Abstract
|
|
{
|
|
Q_OBJECT
|
|
private:
|
|
QMutex mutex;
|
|
sfmt_t sfmt;
|
|
// The discrete cumulative distribution function for the RNG
|
|
unsigned int cdf(unsigned int min, unsigned int max);
|
|
|
|
public:
|
|
explicit RNG_SFMT(uint64_t seed, QObject *parent = nullptr);
|
|
unsigned int rand(int min, int max) override;
|
|
};
|
|
|
|
#endif
|