Bug #73271 [NEW]: Incorrect resp. unneeded OpenSSL feature check

From: Date: Sun, 09 Oct 2016 12:03:42 +0000
Subject: Bug #73271 [NEW]: Incorrect resp. unneeded OpenSSL feature check
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204559@lists.php.net to get a copy of this message
From: rainer dot jung at kippdata dot de Operating system: Solaris, Linux PHP version: 7.1.0RC3 Package: *Compile Issues Bug Type: Bug Bug description:Incorrect resp. unneeded OpenSSL feature check Description: ------------ I stumbled over an invalid OpenSSL feature check. File ext/mysqlnd/config9.m4 contains: AC_CHECK_LIB(ssl, DSA_get_default_method, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later])) AC_CHECK_LIB(crypto, X509_free, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later])) In the first check, it must be "crypto" not "ssl". The symbol DSA_get_default_method is defined in OpenSSL libcrypto, not libssl. The test against the wrong library often fails, but sometimes coincidentally succeeds if due to some other previous check libcrypto was already put into LIBS. Furthermore the second check checks another function, but then sets the same HAVE_DSA_DEFAULT_METHOD define. Now the situation is: - PHP 7.0 and 7.1 already demand OpenSSL 0.9.8 which always has these features. Therefore the same check in ext/openssl/config0.m4 was removed by https://github.com/php/php-src/commit/6a813634052710f3f4bf6e2e03ca1b6c7be3bcee#diff-69bad938d17f4283faa5f7fea17fa627 when the requirement for OpenSSL 0.9.8 was introduced. The same commit also removed the only usage of the define HAVE_DSA_DEFAULT_METHOD (in ext/openssl/openssl.c). So as a followup to this commit I suggest removing the above two lines from ext/mysqlnd/config9.m4 for 7.0 and 7.1: --- ext/mysqlnd/config9.m4 2016-09-29 04:15:39.000000000 +0200 +++ ext/mysqlnd/config9.m4 2016-10-09 13:56:18.351155000 +0200 @@ -34,9 +34,6 @@ test -z "$PHP_OPENSSL" && PHP_OPENSSL=no if test "$PHP_OPENSSL" != "no" || test "$PHP_OPENSSL_DIR" != "no"; then - AC_CHECK_LIB(ssl, DSA_get_default_method, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later])) - AC_CHECK_LIB(crypto, X509_free, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later])) - PHP_SETUP_OPENSSL(MYSQLND_SHARED_LIBADD, [AC_DEFINE(MYSQLND_HAVE_SSL,1,[Enable mysqlnd code that uses OpenSSL directly])]) fi In 5.6 the situation is different. Here the check still makes sense, but should be corrected in ext/mysqlnd/config9.m4 and ext/openssl/config0.m4 to check the right library "crypto" and not "ssl": --- ext/openssl/config0.m4 2016-08-18 13:07:46.000000000 +0200 +++ ext/openssl/config0.m4 2016-10-09 13:58:49.428676000 +0200 @@ -19,7 +19,7 @@ PHP_SETUP_KERBEROS(OPENSSL_SHARED_LIBADD) fi - AC_CHECK_LIB(ssl, DSA_get_default_method, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later])) + AC_CHECK_LIB(crypto, DSA_get_default_method, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later])) AC_CHECK_LIB(crypto, X509_free, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later])) AC_CHECK_FUNCS([RAND_egd]) --- ext/mysqlnd/config9.m4 2016-08-18 13:07:46.000000000 +0200 +++ ext/mysqlnd/config9.m4 2016-10-09 13:58:53.198828000 +0200 @@ -34,7 +34,7 @@ test -z "$PHP_OPENSSL" && PHP_OPENSSL=no if test "$PHP_OPENSSL" != "no" || test "$PHP_OPENSSL_DIR" != "no"; then - AC_CHECK_LIB(ssl, DSA_get_default_method, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later])) + AC_CHECK_LIB(crypto, DSA_get_default_method, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later])) AC_CHECK_LIB(crypto, X509_free, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later])) PHP_SETUP_OPENSSL(MYSQLND_SHARED_LIBADD, [AC_DEFINE(MYSQLND_HAVE_SSL,1,[Enable mysqlnd code that uses OpenSSL directly])]) Regards, Rainer -- Edit bug report at https://bugs.php.net/bug.php?id=73271&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73271&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73271&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73271&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=73271&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=73271&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=73271&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=73271&r=needscript Try newer version: https://bugs.php.net/fix.php?id=73271&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=73271&r=support Expected behavior: https://bugs.php.net/fix.php?id=73271&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=73271&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=73271&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=73271&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73271&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=73271&r=dst IIS Stability: https://bugs.php.net/fix.php?id=73271&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=73271&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=73271&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=73271&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=73271&r=mysqlcfg

« previous php.bugs (#204559) next »