1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
// Copyright 2026 Thomas Zuyev
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
// http://www.apache.org/licenses/LICENSE-2.0
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//! Random utilities backed by the operating system entropy source.
//!
//! Errors returned by this module indicate failure to access OS entropy
//! and are typically unrecoverable in production environments.
use ;
use NonZeroU32;
pub type Result<T> = Result;
pub
pub
pub
/// Using `random % passw_len` to pick a symbol introduces **modulo bias**.
/// This occurs when the range of `random` is not evenly divisible by `passw_len`.
/// For example, if `random` is 0..255 and `passw_len = 12`:
/// - 12 fits into 256 exactly 21 times (21*12 = 252).
/// - The first 4 indices (0..3) occur one extra time compared to the others,
/// so these symbols are slightly more likely to be chosen.
///
/// To avoid this bias, we use **rejection sampling** below:
/// - Generate a random value.
/// - Only accept it if it falls within the largest multiple of `passw_len`
/// that fits in the random range.
/// - Otherwise, discard and retry.
///
/// This ensures each symbol is chosen with equal probability.
pub