crypto/tls: deprecate Config.Rand

We now use SetGlobalRandom in recorded tests.

It was already partially ineffective: ML-KEM encapsulation, used as part
of X25519MLKEM768, doesn't take a source of randomness, and instead
always uses the global random source.

Fixes #79367

Change-Id: I1cc07ebec21bee32ece685efde188c0d6a6a6964
Reviewed-on: https://go-review.googlesource.com/c/go/+/765926
Auto-Submit: Filippo Valsorda <filippo@golang.org>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Roland Shoemaker <roland@golang.org>
Reviewed-by: David Chase <drchase@google.com>
This commit is contained in:
yuhan6665
2026-09-10 21:56:24 -04:00
parent de0813ca88
commit 46c9a6be96
+6 -3
View File
@@ -597,10 +597,13 @@ type Config struct {
LimitFallbackUpload LimitFallback
LimitFallbackDownload LimitFallback
// Rand provides the source of entropy for nonces and RSA blinding.
// Rand provides the source of entropy for the connection.
// If Rand is nil, TLS uses the cryptographic random reader in package
// crypto/rand.
// The Reader must be safe for use by multiple goroutines.
// crypto/rand. The Reader must be safe for use by multiple goroutines.
//
// Deprecated: this should be left nil in production. Not all TLS
// configurations are guaranteed to use Rand. Test code can use
// [testing/cryptotest.SetGlobalRandom] instead.
Rand io.Reader
// Time returns the current time as the number of seconds since the epoch.