Bug #69833 [Asn]: mcrypt broken in 5.6.10 fd caching not working

From: Date: Thu, 06 Aug 2015 20:33:36 +0000
Subject: Bug #69833 [Asn]: mcrypt broken in 5.6.10 fd caching not working
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194989@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69833&edit=1 ID: 69833 Updated by: leigh@php.net Reported by: iand at ekit-inc dot com Summary: mcrypt broken in 5.6.10 fd caching not working Status: Assigned Type: Bug Package: mcrypt related Operating System: Solaris 9,10 PHP Version: 5.6.10 Assigned To: leigh Block user comment: N Private report: N New Comment: I wasn't 100% confident the patch would fix the issue, however it does mean we correctly account for the documented behaviour of open(). I'm not even sure how the issue happens in the first place. Previous Comments: ------------------------------------------------------------------------ [2015-08-06 19:10:55] ab@php.net @iand, @leigh at the first glance the patch doesn't fix the issue in ext/mcrypt. While it's correct to reset the fd after close, MSHUTDOWN doesn't feel like a place fixing it. Does it fix the issue for you? The CSPRNG part looks correct however. Whereby the stuff in the php_random_bytes within if (fd < 0) could be moved into RINIT or even to MINIT, but that's another question. Thanks. ------------------------------------------------------------------------ [2015-08-05 03:23:04] tbmstechnical at gmail dot com Im seeing this issue on php 5.6.11 under apache 2.4.16 with mpm_event_module on Ubuntu 14.04. ------------------------------------------------------------------------ [2015-08-03 12:43:52] leigh@php.net Hi, sorry for the late reply. Yes this affected the CSPRNG fd cache too. Submittd PRs 1450 and 1451 to address MCrypt and random_* respectively to address the fact that the fd can be zero. How it got to be zero is more of a mystery, those read() calls are returning 0 so it looks like it really was /dev/null in Ians trace. ------------------------------------------------------------------------ [2015-06-22 17:55:11] info at regioconnect dot net Can confirm this problem on debian 7 on xen PV. apache 2.4.12, both for php 5.5.26 and 5.6.10 underlying distro is debian wheezy, but apache and php were source compiled. happens with mediawiki 1.25.1: in includes/MWCryptRand.php $iv = mcrypt_create_iv( $rem, MCRYPT_DEV_URANDOM ); changing 2nd parameter to MCRYPT_RAND makes the problem go away. ------------------------------------------------------------------------ [2015-06-16 06:16:20] compi at stz-bg dot com Have the same problem on test server Linux Slackware x64 current. Interesting on produce servers are the same like test server (packages) this problem does not exists, but my test server run on apache2, produce servers on nginx with php-fpm. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69833 -- Edit this bug report at https://bugs.php.net/bug.php?id=69833&edit=1

« previous php.bugs (#194989) next »