Bug #74896 [Asn->Fbk]: sodium's .h defines some functions without .c implementation

From: Date: Sat, 22 Jul 2017 16:04:47 +0000
Subject: Bug #74896 [Asn->Fbk]: sodium's .h defines some functions without .c implementation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210198@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74896&edit=1

 ID:                 74896
 Updated by:         jedisct1@php.net
 Reported by:        requinix@php.net
 Summary:            sodium's .h defines some functions without .c
                     implementation
-Status:             Assigned
+Status:             Feedback
 Type:               Bug
 Package:            Unknown/Other Function
 PHP Version:        master-Git-2017-07-11 (Git)
 Assigned To:        jedisct1
 Block user comment: N
 Private report:     N

 New Comment:

Please try using this snapshot:

  http://snaps.php.net/php-trunk-latest.tar.gz
 
For Windows:

  http://windows.php.net/snapshots/

Hi,

The sodium_randombytes_* symbols have been removed a while back, as PHP now provide similar
functions without this extension (I don't know if the implementation can be defined like in
libsodium, though).

sodium_crypto_aead_xchacha20poly1305_ietf_(en|de)crypt are not duplicates!

These are required for XChaCha20-Poly1305 AEAD implementation, which is the recommended construction
for most applications.

The variant without the "x" should not be used unless compatibility with other libraries
not implementing xchacha20 is required.

This construction was introduced in libsodium 1.0.12, but with some effort we can make it work with
libsodium 1.0.9 as well.


Previous Comments:
------------------------------------------------------------------------
[2017-07-11 07:06:55] requinix@php.net

Related To: Bug #74826

------------------------------------------------------------------------
[2017-07-11 07:05:24] requinix@php.net

Description:
------------
With the libsodium PR merged I did a quick test for functions. php_libsodium.h lists a number of
sodium_* functions however some don't have implementations in libsodium.c.

(I checked all 61 functions and found only the 8 listed below.)

My guess is they should be removed
- encrypt/decrypt look like duplicates of the non-'x'ed versions
- pwhash gets bundled into password_hash/verify()
- randombytes gets bundled into random_bytes()

...but I bet this will be a non-issue when the code gets refactored and cleaned up later anyways.

Test script:
---------------
Given a file "sodium" containing:

sodium_crypto_aead_xchacha20poly1305_ietf_decrypt
sodium_crypto_aead_xchacha20poly1305_ietf_encrypt
sodium_crypto_pwhash
sodium_crypto_pwhash_str
sodium_crypto_pwhash_str_verify
sodium_randombytes_buf
sodium_randombytes_random16
sodium_randombytes_uniform

$ xargs -a sodium -l php --rf | grep Exception

Expected result:
----------------
No output (all functions found)

Actual result:
--------------
Exception: Function sodium_crypto_aead_xchacha20poly1305_ietf_decrypt() does not exist
Exception: Function sodium_crypto_aead_xchacha20poly1305_ietf_encrypt() does not exist
Exception: Function sodium_crypto_pwhash() does not exist
Exception: Function sodium_crypto_pwhash_str() does not exist
Exception: Function sodium_crypto_pwhash_str_verify() does not exist
Exception: Function sodium_randombytes_buf() does not exist
Exception: Function sodium_randombytes_random16() does not exist
Exception: Function sodium_randombytes_uniform() does not exist


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74896&edit=1


Thread (7 messages)

« previous php.bugs (#210198) next »