Radar · Go · Archive · Week 30 · Jul 21 – 27, 2025
crypto: ignore rand io.Reader where behavior is not specified
Worth knowingstdlib
- What changed
- Most crypto APIs will ignore the
io.Readerparameter for randomness and always use the system random source (crypto/internal/sysrand.Read). AGODEBUG=cryptocustomrand=1flag restores the old behavior. A newtesting/cryptotestpackage will allow deterministic randomness in tests. - Production impact
- The source does not say.
- Try it
- Compile a program that calls
rsa.GenerateKeywith a customio.Readerand verify that the key generation no longer depends on that reader. - Source
- github.com/golang/go/issues/70942
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed