Bug #69197 [Ana->Csd]: $extracerts param in openssl_pkcs7_sign handles default values incorrectly

From: Date: Fri, 06 Mar 2015 18:31:52 +0000
Subject: Bug #69197 [Ana->Csd]: $extracerts param in openssl_pkcs7_sign handles default values incorrectly
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191224@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69197&edit=1 ID: 69197 Updated by: rdlowrey@php.net Reported by: marcus at synchromedia dot co dot uk Summary: $extracerts param in openssl_pkcs7_sign handles default values incorrectly -Status: Analyzed +Status: Closed Type: Bug Package: OpenSSL related PHP Version: 5.6.6 Assigned To: rdlowrey Block user comment: N Private report: N New Comment: Automatic comment on behalf of rdlowrey Revision: http://git.php.net/?p=php-src.git;a=commit;h=0928bad9ac9110a8a321c334444b7026bffad5f7 Log: Fixed bug #69197 (openssl_pkcs7_sign handles default value incorrectly) Previous Comments: ------------------------------------------------------------------------ [2015-03-06 17:30:08] marcus at synchromedia dot co dot uk Just to be clear, in my actual code I'm not passing a literal null, but a variable that may contain null or an empty string. It behaves the same way as passing the literal values, so I chose not to complicate it by including that. ------------------------------------------------------------------------ [2015-03-06 17:16:28] marcus at synchromedia dot co dot uk Description: ------------ This is the signature for the openssl_pkcs7_sign function: function openssl_pkcs7_sign($infilename, $outfilename, $signcert, $privkey, array $headers, $flags = PKCS7_DETACHED, $extracerts = null) { } The problem I've found is that if you provide the $extracerts param *at all*, even if it's null (i.e. the same as its default value), it tries to open it as a file, resulting in this error: Warning: openssl_pkcs7_sign(): error opening the file To behave like other PHP functions, I would expect this value to be ignored when passwed with the same value as the default. It appears to be checking for the presence of the parameter rather than its value. It's easy enough to work around - you can check whether you need the extracerts param and have two different calls - but it's still a bug! There are also issues with documentation of the parameters for this function - I've found the $signcert and $privkey params require that you prepend the pathname with 'file://', but, inconsistently, the $extracerts param does not. Test script: --------------- Example script to demonstrate the bug: https://gist.github.com/Synchro/b9e4625013077def0cf7 A successful run should produce no output at all Actual result: -------------- Warning: openssl_pkcs7_sign(): error opening the file, in openssl_pkcs7_sign_bug.php on line 46 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69197&edit=1

« previous php.bugs (#191224) next »