Skip to content

fix(sse): unbiased crypto.randomInt for combo selection (follow-up to #4457) - #4462

Merged
diegosouzapw merged 1 commit into
release/v3.8.32from
fix/codeql-biased-crypto-v3832
Jun 21, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.32from
fix/codeql-biased-crypto-v3832

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Follow-up to #4457 (already merged into release/v3.8.32).

#4457 cleared CodeQL js/insecure-randomness by routing combo target selection / deck
rotation / shadow sampling through node:crypto, but built secureRandomInt as
Math.floor(cryptoFloat() * n). Dividing/rounding a cryptographic value introduces modulo
bias — CodeQL js/biased-cryptographic-random, which #4455's analysis raised on main.

This switches the production integer path to crypto.randomInt(n) (unbiased rejection
sampling). The test-only float seam still scales a float for the deterministic selection
tests, but no crypto value is divided/rounded into a biased integer in production.
secureRandomFloat is unchanged (its [0,1) value is only used in a weighted threshold /
sample-rate comparison, never rounded to a bounded index).

Scope: 1 file (src/shared/utils/secureRandom.ts). Selection behavior + all migrated
test assertions unchanged. eslint + typecheck:core clean; secure-random-routing +
combo-routing-engine green (86/86). The mainline fix is in #4455 (→ main, the branch
CodeQL scans).

…4457)

#4457 routed combo/deck/shadow selection RNG through node:crypto to clear CodeQL
js/insecure-randomness, but built secureRandomInt as Math.floor(cryptoFloat() * n) —
dividing/rounding a cryptographic value introduces modulo bias (CodeQL
js/biased-cryptographic-random, raised on main by #4455's analysis).

Use crypto.randomInt(n) (unbiased rejection sampling) on the production integer path; the
test-only float seam still scales a float for deterministic selection tests, but no crypto
value is divided/rounded into a biased integer in production. secureRandomFloat is unchanged
(its [0,1) value is only used in a weighted threshold / sample-rate comparison, never rounded
to a bounded index). Selection behavior and all migrated test assertions are unchanged.
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@diegosouzapw
diegosouzapw merged commit 3b69960 into release/v3.8.32 Jun 21, 2026
4 checks passed
diegosouzapw added a commit that referenced this pull request Jun 21, 2026
Release v3.8.32 — see CHANGELOG.md [3.8.32] for the full list. Merged via --admin over documented non-blocking checks: CodeQL alerts ratchet (#665 fixed by #4457/#4462, auto-closes on main rescan), Integration Tests (env-flaky batch-upstream), SonarCloud/SonarQube (advisory new-code).
@diegosouzapw
diegosouzapw deleted the fix/codeql-biased-crypto-v3832 branch June 21, 2026 12:33
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
Release v3.8.32 — see CHANGELOG.md [3.8.32] for the full list. Merged via --admin over documented non-blocking checks: CodeQL alerts ratchet (diegosouzapw#665 fixed by diegosouzapw#4457/diegosouzapw#4462, auto-closes on main rescan), Integration Tests (env-flaky batch-upstream), SonarCloud/SonarQube (advisory new-code).
Poid-ZA pushed a commit to Poid-ZA/OmniRoute that referenced this pull request Aug 5, 2026
Release v3.8.32 — see CHANGELOG.md [3.8.32] for the full list. Merged via --admin over documented non-blocking checks: CodeQL alerts ratchet (diegosouzapw#665 fixed by diegosouzapw#4457/diegosouzapw#4462, auto-closes on main rescan), Integration Tests (env-flaky batch-upstream), SonarCloud/SonarQube (advisory new-code).
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Release v3.8.32 — see CHANGELOG.md [3.8.32] for the full list. Merged via --admin over documented non-blocking checks: CodeQL alerts ratchet (diegosouzapw#665 fixed by diegosouzapw#4457/diegosouzapw#4462, auto-closes on main rescan), Integration Tests (env-flaky batch-upstream), SonarCloud/SonarQube (advisory new-code).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant