gofiber/fiber · error
rand.Read failed
Error message
rand.Read failed: %w
What it means
unsafeRandString reads n bytes from crypto/rand in one shot to build a random string (used for multipart boundaries). This error wraps the rare case where rand.Read fails on the very first bulk read, meaning the system random source is unavailable.
Solutions
- Ensure /dev/urandom is available and readable inside the container/sandbox.
- If running under seccomp/AppArmor, allow the getrandom syscall.
- Treat the error as fatal for the request rather than retrying — the source itself is broken.
Defensive patterns
Strategy: fallback
Prevention
- Ensure /dev/urandom is mounted and readable in the deployment.
- Permit the getrandom syscall under seccomp/AppArmor.
- Treat persistent rand failures as a host health incident, not a per-request retry.
When it happens
Trigger: The OS entropy pool is exhausted or /dev/urandom is unreadable; running in a severely locked-down sandbox or container that blocks the random source; an OS-level error from getrandom(2).
Common situations: Heavily restricted containers/seccomp filters that deny getrandom; chroots without /dev/urandom mounted; very early boot on embedded systems.
Related errors
- boundary generation
- set boundary error
- create file error
- failed to close multipart writer
- failed to copy file data
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/9125460c050782f8.
Report an issue: GitHub.
Appendix: source
Thrown at client/hooks.go:53
letterBytes = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789"
)
// unsafeRandString returns a random string of length n.
// An error is returned if the random source fails.
func unsafeRandString(n int) (string, error) {
inputLength := byte(len(letterBytes))
// Compute the largest multiple of inputLength ≤ 256 to avoid modulo bias.
// Any byte ≥ max will be rejected and re‑read.
maxLength := byte(256 - (256 % int(inputLength))) //nolint:gosec // G115: integer overflow conversion int -> byte
out := make([]byte, n)
buf := make([]byte, n)
// Read n raw bytes in one shot
if _, err := rand.Read(buf); err != nil {
return "", fmt.Errorf("rand.Read failed: %w", err)
}
for i, b := range buf {
// Reject values ≥ maxLength
for b >= maxLength {
if _, err := rand.Read(buf[i : i+1]); err != nil {
return "", fmt.Errorf("rand.Read failed: %w", err)
}
b = buf[i]
}
out[i] = letterBytes[b%inputLength]
}
return utils.UnsafeString(out), nil
}
// parserRequestURL sets options for the hostclient and normalizes the URL.
// It merges the baseURL with the request URI if needed and applies query and path parameters.View on GitHub (pinned to a105acad6c)