Bug #69833 [Com]: mcrypt broken in 5.6.10 fd caching not working

From: Date: Mon, 03 Aug 2015 12:43:55 +0000
Subject: Bug #69833 [Com]: mcrypt broken in 5.6.10 fd caching not working
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194931@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69833&edit=1 ID: 69833 Comment by: leigh@php.net Reported by: iand at ekit-inc dot com Summary: mcrypt broken in 5.6.10 fd caching not working Status: Assigned Type: Bug Package: mcrypt related Operating System: Solaris 9,10 PHP Version: 5.6.10 Assigned To: leigh Block user comment: N Private report: N New Comment: Hi, sorry for the late reply. Yes this affected the CSPRNG fd cache too. Submittd PRs 1450 and 1451 to address MCrypt and random_* respectively to address the fact that the fd can be zero. How it got to be zero is more of a mystery, those read() calls are returning 0 so it looks like it really was /dev/null in Ians trace. Previous Comments: ------------------------------------------------------------------------ [2015-06-22 17:55:11] info at regioconnect dot net Can confirm this problem on debian 7 on xen PV. apache 2.4.12, both for php 5.5.26 and 5.6.10 underlying distro is debian wheezy, but apache and php were source compiled. happens with mediawiki 1.25.1: in includes/MWCryptRand.php $iv = mcrypt_create_iv( $rem, MCRYPT_DEV_URANDOM ); changing 2nd parameter to MCRYPT_RAND makes the problem go away. ------------------------------------------------------------------------ [2015-06-16 06:16:20] compi at stz-bg dot com Have the same problem on test server Linux Slackware x64 current. Interesting on produce servers are the same like test server (packages) this problem does not exists, but my test server run on apache2, produce servers on nginx with php-fpm. ------------------------------------------------------------------------ [2015-06-15 08:53:37] iand at ekit-inc dot com Hi Leigh; can you elaborate on how I can test that please. Thanks. Ian D ------------------------------------------------------------------------ [2015-06-15 07:11:53] nikic@php.net @leigh: Please also check whether this applies to the CSPRNG as well. ------------------------------------------------------------------------ [2015-06-15 04:40:16] iand at ekit-inc dot com Description: ------------ mcrypt has broken in 5.6.10 on my platform under apache 2.4.12 running with threaded mpm. $ /opt/local/apache/bin/httpd -M |grep mpm mpm_worker_module (static) Symptoms are that under apache, php's use of mcrypt runs into time limits... but if you run the same code from php command line it works fine. Fatal error: Maximum execution time of 30 seconds exceeded in /opt/local/apache/htdocs/mcr.php on line 7 Inspection with truss shows it is failing to open /dev/urandom This is a truss from apache 2.4.12 with php 5.6.9: 24686/27: munmap(0xCD3B0000, 4096) = 0 24686/27: munmap(0xCD390000, 7880) = 0 24686/27: munmap(0xCD3A1000, 5040) = 0 24686/27: munmap(0xCD370000, 2724) = 0 24686/27: munmap(0xCD380000, 3028) = 0 24686/27: open("/dev/urandom", O_RDONLY) = 17 24686/27: read(17, "02F7F1F1 3CA $A8", 8) = 8 24686/27: close(17) = 0 24686/27: open("/opt/local/lib/libmcrypt/tripledes.la", O_RDONLY) = 17 whereas on apache 2.4.12/php 5.6.10 (below) it keeps reading from fd #0 (lsof says this is /dev/null) until the timeout is reached. 25529/27: munmap(0xCD3B0000, 4096) = 0 25529/27: munmap(0xCD390000, 7880) = 0 25529/27: munmap(0xCD3A1000, 5040) = 0 25529/27: munmap(0xCD370000, 2724) = 0 25529/27: munmap(0xCD380000, 3028) = 0 25529/27: read(0, 0x0853CF78, 8) = 0 25529/27: read(0, 0x0853CF78, 8) = 0 25529/27: read(0, 0x0853CF78, 8) = 0 25529/27: read(0, 0x0853CF78, 8) = 0 25529/27: read(0, 0x0853CF78, 8) = 0 Looking at the php change log for 5.6.10 and the related changes in mcrypt.c it would seem that the changes here have caused this fail. Looking at these changes, I can spot one obvious error; the close code doesn't consider fd#0 an open fd. Patch for this below. However I suspect there is something else going on perhaps related to the multi-threaded environment. $ diff -c mcrypt.c.orig mcrypt.c *** mcrypt.c.orig Wed Jun 10 07:42:27 2015 --- mcrypt.c Mon Jun 15 03:33:18 2015 *************** *** 450,461 **** php_stream_filter_unregister_factory("mcrypt.*" TSRMLS_CC); php_stream_filter_unregister_factory("mdecrypt.*" TSRMLS_CC); ! if (MCG(fd[RANDOM]) > 0) { close(MCG(fd[RANDOM])); } ! if (MCG(fd[URANDOM]) > 0) { close(MCG(fd[URANDOM])); } UNREGISTER_INI_ENTRIES(); --- 450,463 ---- php_stream_filter_unregister_factory("mcrypt.*" TSRMLS_CC); php_stream_filter_unregister_factory("mdecrypt.*" TSRMLS_CC); ! if (MCG(fd[RANDOM]) >= 0) { close(MCG(fd[RANDOM])); + MCG(fd[RANDOM]) = -1; } ! if (MCG(fd[URANDOM]) >= 0) { close(MCG(fd[URANDOM])); + MCG(fd[URANDOM]) = -1; } UNREGISTER_INI_ENTRIES(); ----------- So further debugging is required. Test script: --------------- <?php $plaintext="hello world"; $key = "1;lk23GH2KJ:l*&^$^%$913S"; $encrypted = bin2hex(mcrypt_encrypt(MCRYPT_3DES,$key,$plaintext,MCRYPT_MODE_ECB,mcrypt_create_iv(mcrypt_get_iv_size(MCRYPT_3DES,MCRYPT_MODE_CFB)))); $decrypted_data = trim(mcrypt_decrypt(MCRYPT_3DES,$key,hex2bin($encrypted),MCRYPT_MODE_ECB,mcrypt_create_iv(mcrypt_get_iv_size(MCRYPT_3DES,MCRYPT_MODE_CFB))), "\0"); print "orig=".$plaintext."\n"; print "encr=".$encrypted."\n"; print "decrypted=".$decrypted_data."\n"; if($plaintext != $decrypted_data) { print "MISMATCH\n"; } else { print "MATCH\n"; } ?> Expected result: ---------------- Instant; no timeout Actual result: -------------- timeout ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69833&edit=1

« previous php.bugs (#194931) next »