Bug #75409 [Com]: accept EFAULT in addition to ENOSYS as indicator that getrandom() is missing

From: Date: Sat, 21 Oct 2017 18:11:19 +0000
Subject: Bug #75409 [Com]: accept EFAULT in addition to ENOSYS as indicator that getrandom() is missing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211807@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75409&edit=1

 ID:                 75409
 Comment by:         security at paragonie dot com
 Reported by:        martin dot zdrahal at s-team dot at
 Summary:            accept EFAULT in addition to ENOSYS as indicator
                     that getrandom() is missing
 Status:             Assigned
 Type:               Bug
 Package:            *Encryption and hash functions
 Operating System:   Linux
 PHP Version:        7.1.10
 Assigned To:        sammyk
 Block user comment: N
 Private report:     N

 New Comment:

EPERM is not supposed to be returned by this system call. That means that QNAP is behaving weirdly
and the problem should be fixed on their side.

If a QNAP-specific workaround is desired, first we will need to ensure it's only ever employed
on QNAP kernels. Is there a way to detect them at compile-time?


Previous Comments:
------------------------------------------------------------------------
[2017-10-20 19:49:48] nikic@php.net

I'm a bit skeptical here. I can understand handling EPERM, but EFAULT would generally imply an
error on *our* side, not something that should be silently ignored.

------------------------------------------------------------------------
[2017-10-20 19:43:16] kalle@php.net

Assigning to Sammy, our random_*() magic implementor guy :)

------------------------------------------------------------------------
[2017-10-20 09:44:27] martin dot zdrahal at s-team dot at

Description:
------------
When running php -r '\random_int(0,20);' on my QNAP NAS, PHP always returns an error. The
kernel on my NAS returns EPERM instead of ENOSYS, thus degrading to /dev/urandom does not happen.
This has been fixed in python a while back (https://bugs.python.org/issue27955, albeit it does not
catch EFAULT).

I suspect this behaviour exists in every PHP version that uses the getrandom() syscall

Test script:
---------------
\random_int(0,20);

Actual result:
--------------
PHP Fatal error:  Uncaught Exception: Could not gather sufficient random data in Command line code:1
Stack trace:
#0 Command line code(1): random_int(0, 20)
#1 {main}
  thrown in Command line code on line 1

strace output:

getrandom(0xbde13510, 4, 0)             = -1 EFAULT (Bad address)
brk(0xb6587000)                         = 0xb6587000
writev(2, [{iov_base="", iov_len=0}, {iov_base="PHP Fatal error:  Uncaught
Excep"..., iov_len=206}], 2PHP Fatal error:  Uncaught Exception: Could not gather sufficient
random data in Command line code:1
Stack trace:
#0 Command line code(1): random_int(0, 20)
#1 {main}
  thrown in Command line code on line 1) = 206
writev(2, [{iov_base="\n", iov_len=1}, {iov_base=NULL, iov_len=0}], 2


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=75409&edit=1


Thread (7 messages)

« previous php.bugs (#211807) next »