clientsession 0.7.3.5 → 0.7.3.6
raw patch · 2 files changed
+17/−14 lines, 2 filesdep +taggedPVP ok
version bump matches the API change (PVP)
Dependencies added: tagged
API changes (from Hackage documentation)
Files
- clientsession.cabal +2/−1
- src/Web/ClientSession.hs +15/−13
clientsession.cabal view
@@ -1,5 +1,5 @@ name: clientsession-version: 0.7.3.5+version: 0.7.3.6 license: BSD3 license-file: LICENSE author: Michael Snoyman <michael@snoyman.com>, Felipe Lessa <felipe.lessa@gmail.com>@@ -25,6 +25,7 @@ , bytestring >= 0.9 && < 0.10 , cereal >= 0.3 && < 0.4 , directory >= 1 && < 1.2+ , tagged >= 0.1 , crypto-api >= 0.6.4 && < 0.9 , cryptocipher >= 0.2.5 , skein >= 0.1 && < 0.2
src/Web/ClientSession.hs view
@@ -70,9 +70,13 @@ -- from cereal import Data.Serialize (encode, decode) +-- from tagged+import Data.Tagged (Tagged, untag)+ -- from crypto-api import Crypto.Classes (buildKey)-import Crypto.Random (reseed)+import Crypto.Random (genSeedLength, reseed)+import Crypto.Types (ByteLength) import qualified Crypto.Modes as Modes -- from cryptocipher@@ -235,20 +239,18 @@ -- | Reseed the CPRNG with new entropy from the system pool. aesReseed :: IO () aesReseed = do- ent <- getEntropy 64 -- XXX: Is it possible for getEntropy- -- to return less entropy than- -- than we asked it? I assume "no",- -- but there's a check here just- -- in case.- if S.length ent < 64- then I.atomicModifyIORef aesRef $+ let len :: Tagged AESRNG ByteLength+ len = genSeedLength+ ent <- getEntropy (untag len)+ I.atomicModifyIORef aesRef $+ \(ASt rng _) ->+ case reseed ent rng of+ Right rng' -> (ASt rng' 0, ())+ Left _ -> (ASt rng 0, ()) -- Use the old RNG, but force a reseed -- after another 'threshold' uses of it.- \(ASt rng _) -> (ASt rng 0, ())- else I.atomicModifyIORef aesRef $- \(ASt rng _) ->- let Right rng' = reseed ent rng- in (ASt rng' 0, ())+ -- In theory, we will never reach this+ -- branch, but if we do, we're safe. -- | 'IORef' that keeps the current state of the CPRNG. Yep, -- global state. Used in thread-safe was only, though.