Skip to content

expat asks for entropy the graph has - #451

Merged
Sunrisepeak merged 1 commit into
mainfrom
expat-asks-for-entropy-the-graph-has
Sep 20, 2026
Merged

Sunrisepeak merged 1 commit into
mainfrom
expat-asks-for-entropy-the-graph-has

Conversation

@Sunrisepeak

Copy link
Copy Markdown
Member

The defect

lib/expat_config.h is one static header shared by every target, and it carried #define HAVE_ARC4RANDOM_BUF 1 from a glibc configure run. Over openkal-musl the member stopped at:

xmlparse.c:977:3: error: call to undeclared function `arc4random_buf`

musl 1.2.5 has no arc4random at all — its src/prng/ is the rand48 family, and the name appears in no header. So this is a recipe claiming a function for hosts that do not have it, not a gap in the C library. (The measurement had it filed under the latter; reading musl settled it.)

Why the fallbacks never ran

The macro short-circuits the whole chain:

#if defined(HAVE_ARC4RANDOM_BUF)
  arc4random_buf(&entropy, sizeof(entropy));
#elif defined(HAVE_ARC4RANDOM)
#else
  /* Try high quality providers first .. */
#  elif defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM)

Undefined, the chain falls to HAVE_GETRANDOM — already defined in this same header, and provided by both musl and glibc — then to XML_DEV_URANDOM. No target loses a high-quality entropy source.

Verification

Built against the published stack (openkal-linux 0.15.0, openkal-musl 0.18.0, openkal-llvm-runtime 0.13.0) with this checkout as a live index:

  • expat 2.7.1 compiles
  • the program links and runs
  • nm -u on the artefact shows no arc4random symbol

`lib/expat_config.h` is one static header shared by every target, and it
carried `#define HAVE_ARC4RANDOM_BUF 1` from a glibc configure run. Over
openkal-musl the member stopped at

    xmlparse.c:977:3: error: call to undeclared function 'arc4random_buf'

musl 1.2.5 has no arc4random at all --- its `src/prng/` is the rand48 family,
and the name appears in no header. This is therefore a recipe that claims a
function for hosts that do not have it, not a gap in the C library.

THE MACRO SHORT-CIRCUITS THE WHOLE CHAIN, which is why the fallbacks below it
never ran. `generate_hash_secret_salt` reads:

    #if defined(HAVE_ARC4RANDOM_BUF)
      arc4random_buf(&entropy, sizeof(entropy));
    #elif defined(HAVE_ARC4RANDOM)
    #else
      /* Try high quality providers first .. */
    #  elif defined(HAVE_GETRANDOM) || defined(HAVE_SYSCALL_GETRANDOM)

Undefined, the chain falls to `HAVE_GETRANDOM`, already defined in this same
header and provided by both musl and glibc, and then to `XML_DEV_URANDOM`. No
target loses a high-quality entropy source; the glibc hosts that were reaching
arc4random_buf reach getrandom instead.

Verified against the published stack --- openkal-linux 0.15.0, openkal-musl
0.18.0, openkal-llvm-runtime 0.13.0 --- with this checkout as a live index:
expat 2.7.1 compiles and the program links and runs, and the artefact
references no arc4random symbol.
@Sunrisepeak
Sunrisepeak merged commit bf62dd5 into main Sep 20, 2026
16 checks passed
@Sunrisepeak
Sunrisepeak deleted the expat-asks-for-entropy-the-graph-has branch September 20, 2026 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant