[PR #6836] [management] remove old math rand lib #27217

Open
opened 2026-08-05 07:08:23 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6836
Author: @pascal-fischer
Created: 7/20/2026
Status: 🔄 Open

Base: mainHead: fix/remove-math-rand


📝 Commits (5)

  • 4e9effc remove old math rand lib
  • 0785f37 input validation for peer ip allocation
  • eb43bc8 Merge branch 'main' into fix/remove-math-rand
  • 09f0700 fix import
  • 0dda165 update alias

📊 Changes

10 files changed (+109 additions, -73 deletions)

View changed files

📝 management/internals/modules/agentnetwork/labelgen/labelgen.go (+6 -6)
📝 management/internals/modules/agentnetwork/labelgen/labelgen_test.go (+8 -17)
📝 management/internals/modules/agentnetwork/manager.go (+1 -10)
📝 management/server/account.go (+2 -4)
📝 management/server/group_ipv6_test.go (+1 -2)
📝 management/server/idp/util.go (+9 -7)
📝 management/server/types/aliases.go (+2 -3)
📝 management/server/util/util.go (+15 -0)
📝 shared/management/types/network.go (+37 -24)
📝 shared/management/types/network_test.go (+28 -0)

📄 Description

Describe your changes

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.

Summary by CodeRabbit

  • Bug Fixes
    • Improved validation for unsupported/invalid IPv4 prefixes during peer IP allocation.
    • IPv4 allocation now ignores non-IPv4 addresses in the taken set.
  • Security/Randomness Improvements
    • Passwords, subdomain labels, cache expiration jitter, and IP/subnet selection now use cryptographically secure randomness.
  • API Updates
    • Internal allocation helpers no longer require caller-provided RNGs.
  • Tests
    • Added coverage for invalid IPv4 prefixes and mixed taken-IP lists; updated label selection tests.

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6836 **Author:** [@pascal-fischer](https://github.com/pascal-fischer) **Created:** 7/20/2026 **Status:** 🔄 Open **Base:** `main` ← **Head:** `fix/remove-math-rand` --- ### 📝 Commits (5) - [`4e9effc`](https://github.com/netbirdio/netbird/commit/4e9effcf4cfec98e6ca56558186efcb4095877e6) remove old math rand lib - [`0785f37`](https://github.com/netbirdio/netbird/commit/0785f379a2770c8e7632f347131973cc0f55b094) input validation for peer ip allocation - [`eb43bc8`](https://github.com/netbirdio/netbird/commit/eb43bc8b3596b349cdbdfedeabc4395eb0dfc032) Merge branch 'main' into fix/remove-math-rand - [`09f0700`](https://github.com/netbirdio/netbird/commit/09f0700bb653f9936d350367dd37fd921e7b0275) fix import - [`0dda165`](https://github.com/netbirdio/netbird/commit/0dda165230c3eb54a7c4da006ee612fcd7c33b22) update alias ### 📊 Changes **10 files changed** (+109 additions, -73 deletions) <details> <summary>View changed files</summary> 📝 `management/internals/modules/agentnetwork/labelgen/labelgen.go` (+6 -6) 📝 `management/internals/modules/agentnetwork/labelgen/labelgen_test.go` (+8 -17) 📝 `management/internals/modules/agentnetwork/manager.go` (+1 -10) 📝 `management/server/account.go` (+2 -4) 📝 `management/server/group_ipv6_test.go` (+1 -2) 📝 `management/server/idp/util.go` (+9 -7) 📝 `management/server/types/aliases.go` (+2 -3) 📝 `management/server/util/util.go` (+15 -0) 📝 `shared/management/types/network.go` (+37 -24) 📝 `shared/management/types/network_test.go` (+28 -0) </details> ### 📄 Description ## Describe your changes ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/netbirdio/codesmith/netbird/pr/6836"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with Codesmith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787154679&installation_model_id=427504&pr_number=6836&repository=netbirdio%2Fnetbird&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fnetbird%2Fpull%2F6836&signature=66fe246c2c783f948d8ff439dd16fb913bd87f4851e9468e336aef1f2e5df60d"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img alt="Autofix with Codesmith" src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a> <sup>Need help on this PR? Tag <code>/codesmith</code> with what you need. Autofix is disabled.</sup> <!-- codesmith:autofix:disabled --> <!-- /codesmith:footer --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved validation for unsupported/invalid IPv4 prefixes during peer IP allocation. * IPv4 allocation now ignores non-IPv4 addresses in the taken set. * **Security/Randomness Improvements** * Passwords, subdomain labels, cache expiration jitter, and IP/subnet selection now use cryptographically secure randomness. * **API Updates** * Internal allocation helpers no longer require caller-provided RNGs. * **Tests** * Added coverage for invalid IPv4 prefixes and mixed taken-IP lists; updated label selection tests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 07:08:23 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#27217