pub fn rand_bytes<const N: usize>() -> [u8; N]Expand description
Fill N bytes from the OS cryptographically-secure RNG via the
getrandom crate (getrandom(2) / /dev/urandom on Linux,
getentropy on macOS, BCryptGenRandom on Windows).
Panics if the OS entropy source is unavailable. That only happens on a fundamentally broken platform, and failing loudly (the panic is captured by Sentry) is the right call — minting a guessable secret from a timestamp would be worse than a clean crash.