runtime: call initRand() before initHeap() during initialization.

The reason is that allocating without a heap is usually more visible
than using an uninitialized random generator which is subtle and may
lead to security vulnerabilities.

Based on suggestion from @eliasnaur

Signed-off-by: deadprogram <ron@hybridgroup.com>
This commit is contained in:
deadprogram
2025-12-18 16:26:56 +01:00
committed by Ron Evans
parent 0e540dc3da
commit 82deccac40
5 changed files with 5 additions and 5 deletions
+1 -1
View File
@@ -34,8 +34,8 @@ func wasmEntryReactor() {
// Initialize the heap.
heapStart = uintptr(unsafe.Pointer(&heapStartSymbol))
heapEnd = uintptr(wasm_memory_size(0) * wasmPageSize)
initHeap()
initRand()
initHeap()
if hasScheduler {
// A package initializer might do funky stuff like start a goroutine and
+1 -1
View File
@@ -243,8 +243,8 @@ func sleep(duration int64) {
// run is called by the program entry point to execute the go program.
// With a scheduler, init and the main function are invoked in a goroutine before starting the scheduler.
func run() {
initHeap()
initRand()
initHeap()
go func() {
initAll()
callMain()
+1 -1
View File
@@ -135,8 +135,8 @@ func sleep(duration int64) {
// This function is called on the first core in the system. It will wake up the
// other cores when ready.
func run() {
initHeap()
initRand()
initHeap()
go func() {
// Package initializers are currently run single-threaded.
+1 -1
View File
@@ -21,8 +21,8 @@ var schedulerExit bool
// run is called by the program entry point to execute the go program.
// With the "none" scheduler, init and the main function are invoked directly.
func run() {
initHeap()
initRand()
initHeap()
initAll()
callMain()
mainExited = true
+1 -1
View File
@@ -21,8 +21,8 @@ var (
// Because we just use OS threads, we don't need to do anything special here. We
// can just initialize everything and run main.main on the main thread.
func run() {
initHeap()
initRand()
initHeap()
task.Init(stackTop)
initAll()
callMain()