fix(sse): unbiased crypto.randomInt for combo selection (follow-up to #4457) - #4462
Merged
Merged
Conversation
…4457) #4457 routed combo/deck/shadow selection RNG through node:crypto to clear CodeQL js/insecure-randomness, but built secureRandomInt as Math.floor(cryptoFloat() * n) — dividing/rounding a cryptographic value introduces modulo bias (CodeQL js/biased-cryptographic-random, raised on main by #4455's analysis). Use crypto.randomInt(n) (unbiased rejection sampling) on the production integer path; the test-only float seam still scales a float for deterministic selection tests, but no crypto value is divided/rounded into a biased integer in production. secureRandomFloat is unchanged (its [0,1) value is only used in a weighted threshold / sample-rate comparison, never rounded to a bounded index). Selection behavior and all migrated test assertions are unchanged.
Contributor
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
HouMinXi
pushed a commit
to HouMinXi/OmniRoute
that referenced
this pull request
Aug 2, 2026
Release v3.8.32 — see CHANGELOG.md [3.8.32] for the full list. Merged via --admin over documented non-blocking checks: CodeQL alerts ratchet (diegosouzapw#665 fixed by diegosouzapw#4457/diegosouzapw#4462, auto-closes on main rescan), Integration Tests (env-flaky batch-upstream), SonarCloud/SonarQube (advisory new-code).
Poid-ZA
pushed a commit
to Poid-ZA/OmniRoute
that referenced
this pull request
Aug 5, 2026
Release v3.8.32 — see CHANGELOG.md [3.8.32] for the full list. Merged via --admin over documented non-blocking checks: CodeQL alerts ratchet (diegosouzapw#665 fixed by diegosouzapw#4457/diegosouzapw#4462, auto-closes on main rescan), Integration Tests (env-flaky batch-upstream), SonarCloud/SonarQube (advisory new-code).
tkgo11
pushed a commit
to tkgo11/OmniRoute
that referenced
this pull request
Sep 23, 2026
…iegosouzapw#4457) (diegosouzapw#4462) Integrated into release/v3.8.32
tkgo11
pushed a commit
to tkgo11/OmniRoute
that referenced
this pull request
Sep 23, 2026
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
Release v3.8.32 — see CHANGELOG.md [3.8.32] for the full list. Merged via --admin over documented non-blocking checks: CodeQL alerts ratchet (diegosouzapw#665 fixed by diegosouzapw#4457/diegosouzapw#4462, auto-closes on main rescan), Integration Tests (env-flaky batch-upstream), SonarCloud/SonarQube (advisory new-code).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #4457 (already merged into
release/v3.8.32).#4457 cleared CodeQL
js/insecure-randomnessby routing combo target selection / deckrotation / shadow sampling through
node:crypto, but builtsecureRandomIntasMath.floor(cryptoFloat() * n). Dividing/rounding a cryptographic value introduces modulobias — CodeQL
js/biased-cryptographic-random, which #4455's analysis raised onmain.This switches the production integer path to
crypto.randomInt(n)(unbiased rejectionsampling). The test-only float seam still scales a float for the deterministic selection
tests, but no crypto value is divided/rounded into a biased integer in production.
secureRandomFloatis unchanged (its[0,1)value is only used in a weighted threshold /sample-rate comparison, never rounded to a bounded index).
Scope: 1 file (
src/shared/utils/secureRandom.ts). Selection behavior + all migratedtest assertions unchanged.
eslint+typecheck:coreclean;secure-random-routing+combo-routing-enginegreen (86/86). The mainline fix is in #4455 (→main, the branchCodeQL scans).