drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 1 | /* |
drh | b19a2bc | 2001-09-16 00:13:26 +0000 | [diff] [blame] | 2 | ** 2001 September 15 |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 3 | ** |
drh | b19a2bc | 2001-09-16 00:13:26 +0000 | [diff] [blame] | 4 | ** The author disclaims copyright to this source code. In place of |
| 5 | ** a legal notice, here is a blessing: |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 6 | ** |
drh | b19a2bc | 2001-09-16 00:13:26 +0000 | [diff] [blame] | 7 | ** May you do good and not evil. |
| 8 | ** May you find forgiveness for yourself and forgive others. |
| 9 | ** May you share freely, never taking more than you give. |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 10 | ** |
| 11 | ************************************************************************* |
| 12 | ** This file contains code to implement a pseudo-random number |
| 13 | ** generator (PRNG) for SQLite. |
| 14 | ** |
| 15 | ** Random numbers are used by some of the database backends in order |
| 16 | ** to generate random integer keys for tables or random filenames. |
| 17 | ** |
drh | aedd892 | 2007-01-05 14:38:54 +0000 | [diff] [blame^] | 18 | ** $Id: random.c,v 1.16 2007/01/05 14:38:56 drh Exp $ |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 19 | */ |
| 20 | #include "sqliteInt.h" |
drh | 8cfbf08 | 2001-09-19 13:22:39 +0000 | [diff] [blame] | 21 | #include "os.h" |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 22 | |
drh | af9ff33 | 2002-01-16 21:00:27 +0000 | [diff] [blame] | 23 | |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 24 | /* |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 25 | ** Get a single 8-bit random value from the RC4 PRNG. The Mutex |
| 26 | ** must be held while executing this routine. |
drh | af9ff33 | 2002-01-16 21:00:27 +0000 | [diff] [blame] | 27 | ** |
| 28 | ** Why not just use a library random generator like lrand48() for this? |
drh | f0863fe | 2005-06-12 21:35:51 +0000 | [diff] [blame] | 29 | ** Because the OP_NewRowid opcode in the VDBE depends on having a very |
drh | af9ff33 | 2002-01-16 21:00:27 +0000 | [diff] [blame] | 30 | ** good source of random numbers. The lrand48() library function may |
| 31 | ** well be good enough. But maybe not. Or maybe lrand48() has some |
| 32 | ** subtle problems on some systems that could cause problems. It is hard |
| 33 | ** to know. To minimize the risk of problems due to bad lrand48() |
drh | aaab572 | 2002-02-19 13:39:21 +0000 | [diff] [blame] | 34 | ** implementations, SQLite uses this random number generator based |
drh | af9ff33 | 2002-01-16 21:00:27 +0000 | [diff] [blame] | 35 | ** on RC4, which we know works very well. |
drh | f0863fe | 2005-06-12 21:35:51 +0000 | [diff] [blame] | 36 | ** |
| 37 | ** (Later): Actually, OP_NewRowid does not depend on a good source of |
| 38 | ** randomness any more. But we will leave this code in all the same. |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 39 | */ |
drh | aedd892 | 2007-01-05 14:38:54 +0000 | [diff] [blame^] | 40 | static int randomByte(void){ |
drh | bbd82df | 2004-02-11 09:46:30 +0000 | [diff] [blame] | 41 | unsigned char t; |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 42 | |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 43 | /* All threads share a single random number generator. |
| 44 | ** This structure is the current state of the generator. |
| 45 | */ |
| 46 | static struct { |
drh | bbd82df | 2004-02-11 09:46:30 +0000 | [diff] [blame] | 47 | unsigned char isInit; /* True if initialized */ |
| 48 | unsigned char i, j; /* State variables */ |
| 49 | unsigned char s[256]; /* State variables */ |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 50 | } prng; |
| 51 | |
drh | 90bfcda | 2001-09-23 19:46:51 +0000 | [diff] [blame] | 52 | /* Initialize the state of the random number generator once, |
| 53 | ** the first time this routine is called. The seed value does |
| 54 | ** not need to contain a lot of randomness since we are not |
| 55 | ** trying to do secure encryption or anything like that... |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 56 | ** |
| 57 | ** Nothing in this file or anywhere else in SQLite does any kind of |
| 58 | ** encryption. The RC4 algorithm is being used as a PRNG (pseudo-random |
| 59 | ** number generator) not as an encryption device. |
| 60 | */ |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 61 | if( !prng.isInit ){ |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 62 | int i; |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 63 | char k[256]; |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 64 | prng.j = 0; |
| 65 | prng.i = 0; |
drh | 66560ad | 2006-01-06 14:32:19 +0000 | [diff] [blame] | 66 | sqlite3OsRandomSeed(k); |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 67 | for(i=0; i<256; i++){ |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 68 | prng.s[i] = i; |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 69 | } |
| 70 | for(i=0; i<256; i++){ |
drh | bbd82df | 2004-02-11 09:46:30 +0000 | [diff] [blame] | 71 | prng.j += prng.s[i] + k[i]; |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 72 | t = prng.s[prng.j]; |
| 73 | prng.s[prng.j] = prng.s[i]; |
| 74 | prng.s[i] = t; |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 75 | } |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 76 | prng.isInit = 1; |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 77 | } |
| 78 | |
| 79 | /* Generate and return single random byte |
| 80 | */ |
drh | bbd82df | 2004-02-11 09:46:30 +0000 | [diff] [blame] | 81 | prng.i++; |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 82 | t = prng.s[prng.i]; |
drh | bbd82df | 2004-02-11 09:46:30 +0000 | [diff] [blame] | 83 | prng.j += t; |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 84 | prng.s[prng.i] = prng.s[prng.j]; |
| 85 | prng.s[prng.j] = t; |
drh | bbd82df | 2004-02-11 09:46:30 +0000 | [diff] [blame] | 86 | t += prng.s[prng.i]; |
| 87 | return prng.s[t]; |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 88 | } |
| 89 | |
| 90 | /* |
drh | bbd82df | 2004-02-11 09:46:30 +0000 | [diff] [blame] | 91 | ** Return N random bytes. |
drh | ad75e98 | 2001-10-09 04:19:46 +0000 | [diff] [blame] | 92 | */ |
danielk1977 | 4adee20 | 2004-05-08 08:23:19 +0000 | [diff] [blame] | 93 | void sqlite3Randomness(int N, void *pBuf){ |
drh | bbd82df | 2004-02-11 09:46:30 +0000 | [diff] [blame] | 94 | unsigned char *zBuf = pBuf; |
drh | 66560ad | 2006-01-06 14:32:19 +0000 | [diff] [blame] | 95 | sqlite3OsEnterMutex(); |
drh | bbd82df | 2004-02-11 09:46:30 +0000 | [diff] [blame] | 96 | while( N-- ){ |
| 97 | *(zBuf++) = randomByte(); |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 98 | } |
drh | 66560ad | 2006-01-06 14:32:19 +0000 | [diff] [blame] | 99 | sqlite3OsLeaveMutex(); |
drh | ae85dc8 | 2001-01-13 14:34:05 +0000 | [diff] [blame] | 100 | } |