Bug #71915 [NEW]: openssl_random_pseudo_bytes is not "fork-safe"

From: Date: Tue, 29 Mar 2016 10:01:03 +0000
Subject: Bug #71915 [NEW]: openssl_random_pseudo_bytes is not "fork-safe"
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200205@lists.php.net to get a copy of this message
From:             mathieuk at gmail dot com
Operating system: any
PHP version:      5.6.19
Package:          OpenSSL related
Bug Type:         Bug
Bug description:openssl_random_pseudo_bytes is not "fork-safe"

Description:
------------
In https://github.com/ramsey/uuid/issues/80
it was determined that under
specific circumstances openssl_random_pseudo_bytes may generate
duplicate random values when using a forked process model (like Apache2
prefork MPM or FastCGI) because OpenSSL seeds its random number
generator the first time with a blob of data from /dev/u?random (depends
on config) and then only mixes in the current pid ( pre 20 sept 2013 )
and the current time ( post 20 sept 2013 ) for each call to
RAND_bytes().

This has happened with other projects, like Android, see
http://emboss.github.io/blog/2013/08/21/openssl-prng-is-not-really-fork-safe/
. OpenSSL documents it not being "fork-safe" here:
https://wiki.openssl.org/index.php/Random_fork-safety.


One of the mitigations suggested is calling RAND_poll() after fork().
I've tried to implement such an approach in
https://github.com/php/php-src/commit/afbe15c7e7d2fe650e08f48d62fc4f7928bab695
. It's probably incomplete (maybe reinit_rng() should be called on other
functions too) but I wanted to get feedback first before spending more
time on it. 

Test script:
---------------
https://gist.github.com/mathieuk/63cc6479734b820340b6


-- 
Edit bug report at https://bugs.php.net/bug.php?id=71915&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=71915&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=71915&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=71915&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=71915&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=71915&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=71915&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=71915&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=71915&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=71915&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=71915&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=71915&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=71915&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=71915&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71915&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=71915&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=71915&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=71915&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71915&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=71915&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=71915&r=mysqlcfg



Thread (17 messages)

« previous php.bugs (#200205) next »