Bug #75221 [Ver->Csd]: Argon2i always throws NUL at the end
| From: | cmb@php.net | Date: | Thu, 12 Oct 2017 10:57:45 +0000 |
| Subject: | Bug #75221 [Ver->Csd]: Argon2i always throws NUL at the end | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-211639@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75221&edit=1
ID: 75221
Updated by: cmb@php.net
Reported by: phpdoc at mail dot my1 dot info
Summary: Argon2i always throws NUL at the end
-Status: Verified
+Status: Closed
Type: Bug
Package: *Encryption and hash functions
Operating System: Win8.1 x64
PHP Version: 7.2.0RC2
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=3f8961dfac96a992df2516c0e383e6820eedd31b
Log: Fixed bug #75221 (Argon2i always throws NUL at the end)
Previous Comments:
------------------------------------------------------------------------
[2017-09-18 12:57:18] cmb@php.net
The problem appears to be that argon2_encodedlen() returns the
length of the resulting string including the trailing NUL byte
(i.e. strlen()+1). However, zend_string_alloc() wants the length
of the string without trailing NUL.
See <https://github.com/php/php-src/blob/php-7.2.0beta3/ext/standard/password.c#L518-L529>.
------------------------------------------------------------------------
[2017-09-18 09:56:25] phpdoc at mail dot my1 dot info
by the way, password_verify, doesnt care whether the NUL exists.
the test script can be expanded by:
var_dump(password_verify("php",$pwhash));
var_dump(password_verify("php",trim($pwhash)));
------------------------------------------------------------------------
[2017-09-18 09:40:49] phpdoc at mail dot my1 dot info
Description:
------------
for some reason using argon2i as a hash algorithm, it always dumps out a NUL byte at the end which
doesnt happen with bcrypt.
I just use the PHP7.2-RC2 x64-nts from windows.php.net on a webserver using cgi
Test script:
---------------
<?php
header("Content-type: text/plain");
$pwhash=password_hash("php",PASSWORD_ARGON2I,[
'memory_cost' => 16384, // 16 Mb
'time_cost' => 2,
'threads' => 4,]);
echo $pwhash;
$pwhash2=password_hash("php",PASSWORD_BCRYPT,[
"cost"=> 10]);
echo PHP_EOL.PHP_EOL;
echo $pwhash2;
Expected result:
----------------
that it wont dump a NUL at the end
Actual result:
--------------
it does throw a NUL byte at the end.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75221&edit=1