Skip to content

fix(sse): crypto-secure RNG for combo/deck load-balancing selection (CodeQL #665) - #4455

Merged
diegosouzapw merged 1 commit into
release/v3.8.33from
fix/codeql-insecure-random-combo
Jun 21, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.33from
fix/codeql-insecure-random-combo

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

What

Closes CodeQL alert #665 (js/insecure-randomness, HIGH).

CodeQL flagged Math.random() used for combo target selection (weighted / random /
power-of-two-choices), the credential shuffle deck, and shadow-routing sampling as
"randomness in a security context". These are provider load-balancing decisions —
not secrets, tokens, nonces or session ids — so the finding is a false positive, and
the reported sink (targetExhaustion.ts:59, a plain destructured identifier with zero
data flow) is degenerate. Rather than dismiss, this removes the Math.random sources so
the panel stays clean and the rule cannot re-fire.

How

  • New leaf helper src/shared/utils/secureRandom.ts — secureRandomInt(n) /
    secureRandomFloat() backed by node:crypto, drop-in for
    Math.floor(Math.random()*n) / Math.random() (identical ranges).
  • Replaces all 8 selection-path call sites in targetSorters.ts,
    shadowRouting.ts, shuffleDeck.ts.
  • Test-only _setSecureRandomFloatSource seam (mirrors the existing _resetAllDecks
    export) lets the deterministic selection tests inject a fixed RNG. secureRandomInt
    derives from the same float source, so a given injected value picks the exact same
    index
    Math.floor(Math.random()*n) would have — the 5 migrated tests keep their
    assertions unchanged (no masking).

Tests (Hard Rule #18 — TDD)

  • New tests/unit/secure-random-routing.test.ts: helper range/distribution + a static
    guard that the selection sources contain no Math.random(). Proven RED→GREEN
    (stash sources → guard fails; restore → passes).
  • combo-routing-engine.test.ts (123) + 5 other Math.random-override suites (40) +
    new test (5) all green. typecheck:core, eslint, check:cycles clean.
  • Full test:unit 16445/16461 and test:vitest 192/193 — the handful of reds are
    pre-existing timing/env flakes (chatCore-timeout, rate-limit-semaphore,
    stream-readiness, quota-recorder, opencode dist-not-built, mcp audit sqlite-binding);
    none import this diff and all pass in isolation.

Cherry-pick to release/v3.8.32 follows in a separate PR.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Comment thread src/shared/utils/secureRandom.ts Fixed
…on (CodeQL #665)

CodeQL js/insecure-randomness (#665) flagged Math.random() used for combo target
selection (weighted / random / power-of-two-choices), the credential shuffle deck,
and shadow-routing sampling as "randomness in a security context". These are provider
load-balancing decisions — not secrets, tokens, nonces or session ids — so the finding
is a false positive, and the reported sink (targetExhaustion.ts:59, a plain identifier,
zero data flow) is degenerate. The cleanest durable fix is to remove the Math.random
sources rather than dismiss.

New leaf helper src/shared/utils/secureRandom.ts (secureRandomInt / secureRandomFloat)
backed by node:crypto, a drop-in for Math.floor(Math.random()*n) / Math.random() with
identical ranges. Replaces all 8 selection-path call sites in targetSorters.ts,
shadowRouting.ts and shuffleDeck.ts. A test-only _setSecureRandomFloatSource seam
(mirroring the existing _resetAllDecks export) lets the deterministic selection tests
inject a fixed RNG; secureRandomInt derives from the same float source, so a given
injected value selects the exact same index Math.floor(Math.random()*n) would have —
the migrated assertions are unchanged.

Regression guard: tests/unit/secure-random-routing.test.ts pins the helper ranges and
a static check that the selection sources contain no Math.random().
@github-actions

Copy link
Copy Markdown
Contributor

CI Coverage Report

  • Coverage job: skipped
  • PR test policy: success

Coverage artifact was not available for this run.

@diegosouzapw
diegosouzapw changed the base branch from main to release/v3.8.33 June 21, 2026 14:02
@diegosouzapw
diegosouzapw merged commit f3253ee into release/v3.8.33 Jun 21, 2026
8 checks passed
@diegosouzapw diegosouzapw mentioned this pull request Jun 22, 2026
@diegosouzapw
diegosouzapw deleted the fix/codeql-insecure-random-combo branch June 23, 2026 13:13
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…iegosouzapw#4455)

Replaces Math.random with crypto-secure RNG in combo/deck load-balancing selection (CodeQL diegosouzapw#665).

Integrated into release/v3.8.33.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants