Bug #73271 [NEW]: Incorrect resp. unneeded OpenSSL feature check
| From: | rainer dot jung at kippdata dot de | Date: | Sun, 09 Oct 2016 12:03:42 +0000 |
| Subject: | Bug #73271 [NEW]: Incorrect resp. unneeded OpenSSL feature check | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-204559@lists.php.net to get a copy of this message | ||
From: rainer dot jung at kippdata dot de
Operating system: Solaris, Linux
PHP version: 7.1.0RC3
Package: *Compile Issues
Bug Type: Bug
Bug description:Incorrect resp. unneeded OpenSSL feature check
Description:
------------
I stumbled over an invalid OpenSSL feature check. File
ext/mysqlnd/config9.m4 contains:
AC_CHECK_LIB(ssl, DSA_get_default_method,
AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later]))
AC_CHECK_LIB(crypto, X509_free, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1,
[OpenSSL 0.9.7 or later]))
In the first check, it must be "crypto" not "ssl". The symbol
DSA_get_default_method is defined in OpenSSL libcrypto, not libssl. The
test against the wrong library often fails, but sometimes coincidentally
succeeds if due to some other previous check libcrypto was already put
into LIBS.
Furthermore the second check checks another function, but then sets the
same HAVE_DSA_DEFAULT_METHOD define.
Now the situation is:
- PHP 7.0 and 7.1 already demand OpenSSL 0.9.8 which always has these
features. Therefore the same check in ext/openssl/config0.m4 was removed
by
https://github.com/php/php-src/commit/6a813634052710f3f4bf6e2e03ca1b6c7be3bcee#diff-69bad938d17f4283faa5f7fea17fa627
when the requirement for OpenSSL 0.9.8 was introduced. The same commit
also removed the only usage of the define HAVE_DSA_DEFAULT_METHOD (in
ext/openssl/openssl.c). So as a followup to this commit I suggest
removing the above two lines from ext/mysqlnd/config9.m4 for 7.0 and
7.1:
--- ext/mysqlnd/config9.m4 2016-09-29 04:15:39.000000000 +0200
+++ ext/mysqlnd/config9.m4 2016-10-09 13:56:18.351155000 +0200
@@ -34,9 +34,6 @@
test -z "$PHP_OPENSSL" && PHP_OPENSSL=no
if test "$PHP_OPENSSL" != "no" || test "$PHP_OPENSSL_DIR" !=
"no";
then
- AC_CHECK_LIB(ssl, DSA_get_default_method,
AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later]))
- AC_CHECK_LIB(crypto, X509_free, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD,
1, [OpenSSL 0.9.7 or later]))
-
PHP_SETUP_OPENSSL(MYSQLND_SHARED_LIBADD,
[AC_DEFINE(MYSQLND_HAVE_SSL,1,[Enable mysqlnd code that uses OpenSSL
directly])])
fi
In 5.6 the situation is different. Here the check still makes sense, but
should be corrected in ext/mysqlnd/config9.m4 and ext/openssl/config0.m4
to check the right library "crypto" and not "ssl":
--- ext/openssl/config0.m4 2016-08-18 13:07:46.000000000 +0200
+++ ext/openssl/config0.m4 2016-10-09 13:58:49.428676000 +0200
@@ -19,7 +19,7 @@
PHP_SETUP_KERBEROS(OPENSSL_SHARED_LIBADD)
fi
- AC_CHECK_LIB(ssl, DSA_get_default_method,
AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later]))
+ AC_CHECK_LIB(crypto, DSA_get_default_method,
AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later]))
AC_CHECK_LIB(crypto, X509_free, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1,
[OpenSSL 0.9.7 or later]))
AC_CHECK_FUNCS([RAND_egd])
--- ext/mysqlnd/config9.m4 2016-08-18 13:07:46.000000000 +0200
+++ ext/mysqlnd/config9.m4 2016-10-09 13:58:53.198828000 +0200
@@ -34,7 +34,7 @@
test -z "$PHP_OPENSSL" && PHP_OPENSSL=no
if test "$PHP_OPENSSL" != "no" || test "$PHP_OPENSSL_DIR" !=
"no";
then
- AC_CHECK_LIB(ssl, DSA_get_default_method,
AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later]))
+ AC_CHECK_LIB(crypto, DSA_get_default_method,
AC_DEFINE(HAVE_DSA_DEFAULT_METHOD, 1, [OpenSSL 0.9.7 or later]))
AC_CHECK_LIB(crypto, X509_free, AC_DEFINE(HAVE_DSA_DEFAULT_METHOD,
1, [OpenSSL 0.9.7 or later]))
PHP_SETUP_OPENSSL(MYSQLND_SHARED_LIBADD,
[AC_DEFINE(MYSQLND_HAVE_SSL,1,[Enable mysqlnd code that uses OpenSSL
directly])])
Regards,
Rainer
--
Edit bug report at https://bugs.php.net/bug.php?id=73271&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73271&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73271&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73271&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73271&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73271&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73271&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73271&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73271&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73271&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73271&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73271&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73271&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73271&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73271&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73271&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73271&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73271&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73271&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73271&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73271&r=mysqlcfg