Bug #71087 [NEW]: Phar - cannot use OpenSSL signatures with custom stub
| From: | securtiy at paragonie dot com | Date: | Thu, 10 Dec 2015 21:50:00 +0000 |
| Subject: | Bug #71087 [NEW]: Phar - cannot use OpenSSL signatures with custom stub | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-197778@lists.php.net to get a copy of this message | ||
From: securtiy at paragonie dot com
Operating system: Debian 8.1 Jessie with Dotdeb
PHP version: 5.6.16
Package: PHAR related
Bug Type: Bug
Bug description:Phar - cannot use OpenSSL signatures with custom stub
Description:
------------
Is there any reason why we can't use Phar::setSignatureAlgorithm() after
Phar::setStub()?
https://github.com/defuse/php-encryption/pull/139
If there's a reason this shouldn't allowed, could the documentation
please be updated to reflect this decision?
If this is a bug, it's breaking our ability to publish signed a .phar
for defuse/php-encryption
Test script:
---------------
https://raw.githubusercontent.com/paragonie/php-encryption/29dc5e866bb08dac38fef721f3356f2e2fea76c3/other/build_phar.php
Expected result:
----------------
Silent success, but if I do this:
$phar = new \Phar(dirname(__DIR__).'/dist/defuse-crypto.phar');
$signature = $phar->getSignature();
var_dump($signature);
...it shouldn't say its "hash_type" is "SHA-1"
Actual result:
--------------
PHP Fatal error: Uncaught exception 'PharException' with message
'unable to copy stub of old phar to new phar
"/var/www/defuse/php-encryption/dist/defuse-crypto.phar"' in
/var/www/defuse/php-encryption/other/build_phar.php:37
Stack trace:
#0 /var/www/defuse/php-encryption/other/build_phar.php(37):
Phar->setSignatureAlgorithm(16, '-----BEGIN PRIV...')
#1 {main}
thrown in /var/www/defuse/php-encryption/other/build_phar.php on line
37
--
Edit bug report at https://bugs.php.net/bug.php?id=71087&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71087&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71087&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71087&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71087&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71087&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71087&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71087&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71087&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71087&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71087&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71087&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71087&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71087&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71087&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71087&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71087&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71087&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71087&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71087&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71087&r=mysqlcfg