Edit report at https://bugs.php.net/bug.php?id=67827&edit=1
ID: 67827
Comment by: fa@php.net
Reported by: ncopa at alpinelinux dot org
Summary: [PATCH] broken detection of system crypt
sha256/sha512 support
Status: Open
Type: Bug
Package: *Encryption and hash functions
Operating System: Alpine Linux
PHP Version: 5.5.15
Block user comment: N
Private report: N
New Comment:
Not that I disagree, but it works for me on a 5.5.15 built on Ubuntu 12.04 on Aug 5th:
PHP Version => 5.5.15
Configure Command => './configure' '--prefix=/usr/local/stow/php-5.5.15'
'--with-config-file-path=/etc/php5/5.5.15' '--enable-fpm'
'--with-fpm-user=www-data' '--with-fpm-group=www-data' '--with-gd'
'--enable-zip' '--with-mysqli=mysqlnd' '--with-pdo-mysql=mysqlnd'
'--with-mysql=mysqlnd' '--enable-mbstring' '--with-curl'
'--with-freetype-dir=/usr/include/freetype2' '--enable-gd-native-ttf'
Hashing Engines => md2 md4 md5 sha1 sha224 sha256 sha384 sha512 ripemd128 ripemd160 ripemd256
ripemd320 whirlpool tiger128,3 tiger160,3 tiger192,3 tiger128,4 tiger160,4 tiger192,4 snefru
snefru256 gost adler32 crc32 crc32b fnv132 fnv164 joaat haval128,3 haval160,3 haval192,3 haval224,3
haval256,3 haval128,4 haval160,4 haval192,4 haval224,4 haval256,4 haval128,5 haval160,5 haval192,5
haval224,5 haval256,5
$ /usr/local/stow/php-5.5.15/bin/php -r 'echo CRYPT_SHA256.PHP_EOL;'
1
$ /usr/local/stow/php-5.5.15/bin/php -r 'echo CRYPT_SHA512.PHP_EOL;'
1
Previous Comments:
------------------------------------------------------------------------
[2014-08-12 11:11:45] ncopa at alpinelinux dot org
Description:
------------
the configure script checks for sha256/sha512 support in system crypt(3) and sucessfully finds it.
But it will set PHP_SHA_CRYPT to 0 due to a bad test and the result is that CRYPT_256 and CRYPT_512
constants are wrong set to 0 in runtime.
This happens due to a uppercase vs lowercase mismatch in ext/standard/config.m4:
It start with setting ac_vc_crypt_SHA512 (note uppercase SHA512)
AC_CACHE_CHECK(for SHA512 crypt, ac_cv_crypt_SHA512,[
...
}],[
ac_cv_crypt_SHA512=yes
],[
ac_cv_crypt_SHA512=no
],[
ac_cv_crypt_SHA512=no
])])
But some lines below it checks with lowercase $ac_cv_crypt_sha512:
if test "$ac_cv_crypt_sha512" = "yes"; then
ac_result=1
ac_crypt_sha512=1
else
ac_result=0
ac_crypt_sha512=0
fi
AC_DEFINE_UNQUOTED(PHP_SHA512_CRYPT, $ac_result, [Whether the system supports SHA512 salt])
And it wil end up setting PHP_SHA512_CRYPT to 0 even if we actually have sha512 support. Same thing
happens with sha256.
Test script:
---------------
echo CRYPT_SHA256."\n";
echo CRYPT_SHA512."\n";
Expected result:
----------------
1
Actual result:
--------------
0
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67827&edit=1