From a7ed2329d1c32dd5e83dcfa4ac8d1ff78b663d9b Mon Sep 17 00:00:00 2001 From: fettpl <38704082+fettpl@users.noreply.github.com> Date: Sun, 15 Feb 2026 00:25:20 +0100 Subject: [PATCH] fix: assert variant_match in CSPRNG key entropy test Add missing assertion for variant_match (byte[8] UUID v4 variant bits) which was computed but never checked. Co-Authored-By: Claude Opus 4.6 --- src/security/secrets.rs | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/security/secrets.rs b/src/security/secrets.rs index cd93ede..f78d055 100644 --- a/src/security/secrets.rs +++ b/src/security/secrets.rs @@ -773,6 +773,11 @@ mod tests { "byte[6] matched UUID v4 version nibble {version_match}/100 times — \ likely still using UUID-based key generation" ); + assert!( + variant_match < 50, + "byte[8] matched UUID v4 variant bits {variant_match}/100 times — \ + likely still using UUID-based key generation" + ); } #[cfg(unix)]