{"record":{"id":"9125460c050782f8","repo":"gofiber/fiber","slug":"rand-read-failed-w","errorCode":null,"errorMessage":"rand.Read failed: %w","messagePattern":"rand\\.Read failed: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"client/hooks.go","lineNumber":53,"sourceCode":"\n\tletterBytes = \"abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789\"\n)\n\n// unsafeRandString returns a random string of length n.\n// An error is returned if the random source fails.\nfunc unsafeRandString(n int) (string, error) {\n\tinputLength := byte(len(letterBytes))\n\n\t// Compute the largest multiple of inputLength ≤ 256 to avoid modulo bias.\n\t// Any byte ≥ max will be rejected and re‑read.\n\tmaxLength := byte(256 - (256 % int(inputLength))) //nolint:gosec // G115: integer overflow conversion int -> byte\n\n\tout := make([]byte, n)\n\tbuf := make([]byte, n)\n\n\t// Read n raw bytes in one shot\n\tif _, err := rand.Read(buf); err != nil {\n\t\treturn \"\", fmt.Errorf(\"rand.Read failed: %w\", err)\n\t}\n\n\tfor i, b := range buf {\n\t\t// Reject values ≥ maxLength\n\t\tfor b >= maxLength {\n\t\t\tif _, err := rand.Read(buf[i : i+1]); err != nil {\n\t\t\t\treturn \"\", fmt.Errorf(\"rand.Read failed: %w\", err)\n\t\t\t}\n\t\t\tb = buf[i]\n\t\t}\n\t\tout[i] = letterBytes[b%inputLength]\n\t}\n\n\treturn utils.UnsafeString(out), nil\n}\n\n// parserRequestURL sets options for the hostclient and normalizes the URL.\n// It merges the baseURL with the request URI if needed and applies query and path parameters.","sourceCodeStart":35,"sourceCodeEnd":71,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/client/hooks.go#L35-L71","documentation":"unsafeRandString reads n bytes from crypto/rand in one shot to build a random string (used for multipart boundaries). This error wraps the rare case where rand.Read fails on the very first bulk read, meaning the system random source is unavailable.","triggerScenarios":"The OS entropy pool is exhausted or /dev/urandom is unreadable; running in a severely locked-down sandbox or container that blocks the random source; an OS-level error from getrandom(2).","commonSituations":"Heavily restricted containers/seccomp filters that deny getrandom; chroots without /dev/urandom mounted; very early boot on embedded systems.","solutions":["Ensure /dev/urandom is available and readable inside the container/sandbox.","If running under seccomp/AppArmor, allow the getrandom syscall.","Treat the error as fatal for the request rather than retrying — the source itself is broken."],"exampleFix":null,"handlingStrategy":"fallback","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":["Ensure /dev/urandom is mounted and readable in the deployment.","Permit the getrandom syscall under seccomp/AppArmor.","Treat persistent rand failures as a host health incident, not a per-request retry."],"tags":["client","crypto-rand","multipart","boundary","system"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}