authorGiuseppe D'Angelo <>2012-03-24 08:36:52 +0000
committerQt by Nokia <>2012-04-03 19:12:13 +0200
QHash security fix (1/2): add global QHash seed
Algorithmic complexity attacks against hash tables have been known since 2003 (cf. [1, 2]), and they have been left unpatched for years until the 2011 attacks [3] against many libraries / (reference) implementations of programming languages. This patch adds a global integer, to be used as a seed for the hash function itself. The seed is randomly initialized the first time a QHash detaches from shared_null. Right now the seed is not used at all -- another patch will modify qHash to make use of it. [1] [2] [3] Task-number: QTBUG-23529 Change-Id: I7519e4c02b9c2794d1c14079b01330eb356e9c65 Reviewed-by: Thiago Macieira <>
diff --git a/tools/configure/configure_pch.h b/tools/configure/configure_pch.h
--- a/tools/configure/configure_pch.h
+++ b/tools/configure/configure_pch.h
@@ -39,6 +39,11 @@
+// for rand_s, _CRT_RAND_S must be #defined before #including stdlib.h.
+// put it at the beginning so some indirect inclusion doesn't break it
+#ifndef _CRT_RAND_S
+#define _CRT_RAND_S
#include <qplatformdefs.h>
#include <qglobal.h>
#include <qlist.h>