use rustls::crypto::{GetRandomFailed, SecureRandom};
#[derive(Debug)]
pub struct Random;
impl SecureRandom for Random {
fn fill(&self, buf: &mut [u8]) -> Result<(), GetRandomFailed> {
let mut rng = ic_drbg::Rng::from_os().map_err(|_| GetRandomFailed)?;
rng.fill(buf).map_err(|_| GetRandomFailed)
}
fn fips(&self) -> bool {
false
}
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn the_random_source_produces_fresh_bytes() {
let mut a = [0u8; 32];
let mut b = [0u8; 32];
Random.fill(&mut a).unwrap();
Random.fill(&mut b).unwrap();
assert_ne!(a, b, "two draws were identical");
assert_ne!(a, [0u8; 32], "the buffer was left untouched");
Random.fill(&mut []).unwrap();
let mut big = alloc::vec![0u8; 4096];
Random.fill(&mut big).unwrap();
assert!(big.iter().any(|b| *b != 0));
}
#[test]
fn the_random_source_claims_no_fips_validation() {
assert!(!Random.fips());
}
}