HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Moduleentropy-0.4.1.11Haskell2010

System.Entropy

Obtain entropy from system sources or x86 RDRAND when available.

Currently supporting:

  • Windows via CryptoAPI

  • *nix systems via /dev/urandom

  • Includes QNX

  • ghcjs/browser via JavaScript crypto API.

  • 1 type
  • 5 values
  • Packageentropy-0.4.1.11
  • Exports6
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourceEntropy.hs
valuegetEntropy
  1. :: Int

    Number of bytes

  2. -> IO ByteString
#

Get a specific number of bytes of cryptographically secure random data using the *system-specific* sources. (As of 0.4. Versions <0.4 mixed system and hardware sources)

The returned random value is considered cryptographically secure but not true entropy.

On some platforms this requires a file handle which can lead to resource exhaustion in some situations.

valuegetHardwareEntropy
  1. :: Int

    Number of bytes

  2. -> IO (Maybe ByteString)
#

Get a specific number of bytes of cryptographically secure random data using a supported *hardware* random bit generator.

If there is no hardware random number generator then Nothing is returned. If any call returns non-Nothing then it should never be Nothing unless there has been a hardware failure.

If trust of the CPU allows it and no context switching is important, a bias to the hardware rng with system rng as fall back is trivial:

let fastRandom nr = maybe (getEntropy nr) pure =<< getHardwareEntropy nr

The old, <0.4, behavior is possible using xor from Data.Bits:

let oldRandom nr =
     do hwRnd  maybe (replicate nr 0) BS.unpack <$ getHardwareEntropy nr
        sysRnd BS.unpack <$ getEntropy nr
        pure $ BS.pack $ zipWith xor sysRnd hwRnd

A less maliable mixing can be accomplished by replacing xor with a composition of concat and cryptographic hash.

datadata CryptHandle
#

Handle for manual resource management