fix: use explicit OS entropy for assistant and wallet IDs

This commit is contained in:
archipelago
2026-10-09 08:56:29 -04:00
parent 088eee55b8
commit e2d926f5e0
3 changed files with 5 additions and 4 deletions
+3 -2
View File
@@ -23,7 +23,6 @@ use std::sync::atomic::{AtomicU64, Ordering};
use std::sync::{Arc, Mutex, OnceLock};
use std::time::Duration;
use rand::RngCore;
use serde_json::json;
use sha2::{Digest, Sha256};
use tokio::sync::oneshot;
@@ -227,7 +226,9 @@ pub fn global() -> Arc<ConfirmGate> {
/// nonce for the same action never matches today's pending entry).
pub fn mint_nonce(tool_name: &str, validated_args: &str) -> String {
let mut salt = [0u8; 16];
rand::thread_rng().fill_bytes(&mut salt);
crate::entropy::draw_key_bytes(&mut rand::rngs::OsRng, &mut salt).unwrap_or_else(|e| {
panic!("refusing to mint a confirmation nonce from degenerate entropy: {e} (KEY-05)")
});
let mut hasher = Sha256::new();
hasher.update(salt);
hasher.update(tool_name.as_bytes());
+1 -1
View File
@@ -30,7 +30,7 @@ pub const TOKEN_LEN: usize = 8;
/// wrapped. Called exactly once per [`UntrustedBlock::new`] /
/// [`wrap_untrusted`] invocation.
fn fresh_token() -> String {
rand::thread_rng()
rand::rngs::OsRng
.sample_iter(Alphanumeric)
.take(TOKEN_LEN)
.map(char::from)
+1 -1
View File
@@ -474,7 +474,7 @@ async fn ensure_token(
/// Draw a fresh readable wallet name, Minibits-style: adjective + noun + number.
fn generate_wallet_id() -> String {
let mut rng = rand::thread_rng();
let mut rng = rand::rngs::OsRng;
let adj = ADJECTIVES.choose(&mut rng).copied().unwrap_or("quiet");
let noun = NOUNS.choose(&mut rng).copied().unwrap_or("harbor");
let num = rand::Rng::gen_range(&mut rng, 1..=999);