Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:117960 Return-Path: Delivered-To: mailing list internals@lists.php.net Received: (qmail 91317 invoked from network); 16 Jun 2022 06:37:12 -0000 Received: from unknown (HELO php-smtp4.php.net) (45.112.84.5) by pb1.pair.com with SMTP; 16 Jun 2022 06:37:12 -0000 Received: from php-smtp4.php.net (localhost [127.0.0.1]) by php-smtp4.php.net (Postfix) with ESMTP id BD5DD1804D4 for ; Thu, 16 Jun 2022 01:25:09 -0700 (PDT) X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on php-smtp4.php.net X-Spam-Level: X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,HTML_MESSAGE,RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H2,SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=no autolearn_force=no version=3.4.2 X-Spam-ASN: AS15169 209.85.128.0/17 X-Spam-Virus: No X-Envelope-From: Received: from mail-yb1-f182.google.com (mail-yb1-f182.google.com [209.85.219.182]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by php-smtp4.php.net (Postfix) with ESMTPS for ; Thu, 16 Jun 2022 01:25:09 -0700 (PDT) Received: by mail-yb1-f182.google.com with SMTP id r3so964534ybr.6 for ; Thu, 16 Jun 2022 01:25:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=colopl.co.jp; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=7XLEa6iXHEeNqerEZvxl50ZaKLvCNJnfsMp9vk4iHNw=; b=RKEObumsH94gttcTgXFNx6nLwOPzPj7Nk4DDSOOjpdfXQqa0GHeT3Xrov+Tde2o2W1 jpTL7Snz7LKZC9Z6LlHmpCAJVuaA6W6ewNOUDfQ4n5wPbNggW1m8Irph1S4dz90hZGQ4 S+Bm8JS70fWsC26R5grVRqHUcwpCsDypaeXah+ajVa92nRJzqnnFQY58MjaUidCqPQYf YhFQlNJ+PPj4Y41TdBIESsmg//0lNN+AsyceDW/hC78YSF3Ccv2/cyE124SVgr5OetM1 QF9Sg/1dtixckkfcEYfgXZLgqKTx1pP40v8lviVDHNMmQ4aUZ9o/5ag8+IQEFEKgnnlZ p6QQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=7XLEa6iXHEeNqerEZvxl50ZaKLvCNJnfsMp9vk4iHNw=; b=AKKTJPIlIxOjip7NFYCpnEOFsJzmycW1B8KSvmCfVMcK94Al1k8Z3BQnmLklCYVea0 eeyvIfwV5lofRE+WZlkzvLYWMbK+MQX/GsMh3vj2GgUzvC7PRtt42GlZdr/wJCzkbER9 HOwE5HRpoivAa1N+FlHXHDJut87xoqIQaOOKU6Wn70hIDeFCUn+FjETgdQkfHGhZPV3K NvnyfbsJcY34W7Q5i6t/SmBqIwNAMVy5UUL+6qAftffZkH7amvpLB3eFAdOQnOXltWuS euMpGHGyiK5uUxJ05EMST1OXXi1/K3fAjTe1djEEGEf3vxHSfqtsmYnhAnMqXdbB+a8m 4Vkw== X-Gm-Message-State: AJIora+3UNRgehCznijQ+h2QCiZ5FQfAmU6KLFU1MgmRn1S/3GR2lGW/ KD89q4AzUSqzpiZ969FzBzaCtBrxpPsQgSBlhi2p X-Google-Smtp-Source: AGRyM1tN+5iOY/TIEdrSHL0uOp1rEf3TEoSeKvqBmC80O+llX31evRCTTbb9BapNUobb6DCJJltMMWPsavTww3zZ4iA= X-Received: by 2002:a25:e6c1:0:b0:664:6ef1:b2 with SMTP id d184-20020a25e6c1000000b006646ef100b2mr3737876ybh.579.1655367908227; Thu, 16 Jun 2022 01:25:08 -0700 (PDT) MIME-Version: 1.0 References: In-Reply-To: Date: Thu, 16 Jun 2022 17:24:57 +0900 Message-ID: To: =?UTF-8?Q?Tim_D=C3=BCsterhus?= , internals@lists.php.net Content-Type: multipart/alternative; boundary="00000000000024912905e18c60da" Subject: Re: [PHP-DEV] [RFC] [VOTE] Random Extension 5.x From: g-kudo@colopl.co.jp (Go Kudo) --00000000000024912905e18c60da Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable 2022=E5=B9=B46=E6=9C=8816=E6=97=A5(=E6=9C=A8) 2:23 Tim D=C3=BCsterhus : > Hi > > On 6/14/22 02:01, Go Kudo wrote: > > Voting began on 2022-06-14 00:00:00 (UTC) and will end on 2022-06-28 > > 00:00:00 (UTC). > > > > https://wiki.php.net/rfc/rng_extension > > > > The implementation is not yet complete and has some issues. > > See TODO in Pull Request for details. > > > > https://github.com/php/php-src/pull/8094 > > > > Unfortunately the vote has already started and I'm not sure if that's a > change that might change the outcome of the vote, but while looking > through the implementation once more I noticed that the engine > implementations are not 'final' (and extending those engines is actually > tested with the existing tests). > > However I believe they should be final: > > a) I generally believe that it's a best practice to make everything > 'final' by default. > > b) It's easily possible to use composition with engines, as the > interface only has a single method. > > c) Especially for 'Random\Engine\Secure' I believe that allowing > subclassing is actively harmful, as basically any adjustment of the > engine's behavior violates the contract that the engine returns > cryptographically secure randomness. But also for other engines changing > the behavior also changes the implied behavior given by the engine's name= . > > What do you think? > > Best regards > Tim D=C3=BCsterhus > Hi Tim > However I believe they should be final That is correct, indeed. The interface is already provided and creating a composition is easy. However, the voting has already started. It would be impossible to edit the RFC now. Fortunately, the Feature Freeze for PHP 8.2 is 7/19. Even after the current Random Extension 5.x RFC voting is over, there is still time to create and vote on RFCs to make changes. I will create an additional RFC like PHP 8.0 Attribute. Regards Go Kudo --00000000000024912905e18c60da--