Edit report at https://bugs.php.net/bug.php?id=75409&edit=1
ID: 75409
Comment by: security at paragonie dot com
Reported by: martin dot zdrahal at s-team dot at
Summary: accept EFAULT in addition to ENOSYS as indicator
that getrandom() is missing
Status: Assigned
Type: Bug
Package: *Encryption and hash functions
Operating System: Linux
PHP Version: 7.1.10
Assigned To: sarciszewski
Block user comment: N
Private report: N
New Comment:
This should fix this issue. I hope the fix can be backported into 7.0, 7.1, and 7.2 for the next,
next, and first (respectively) releases.
https://github.com/php/php-src/pull/2932/commits/9aadac9778096290c6d85946fabbe5c883a9f723
Previous Comments:
------------------------------------------------------------------------
[2017-10-21 18:17:24] security at paragonie dot com
After checking with Frank Denis, all responses except EINTR or EAGAIN should fallback to
/dev/urandom. https://twitter.com/jedisct1/status/921801560006504450
So, let's make sure that is happening.
------------------------------------------------------------------------
[2017-10-21 18:11:15] security at paragonie dot com
EPERM is not supposed to be returned by this system call. That means that QNAP is behaving weirdly
and the problem should be fixed on their side.
If a QNAP-specific workaround is desired, first we will need to ensure it's only ever employed
on QNAP kernels. Is there a way to detect them at compile-time?
------------------------------------------------------------------------
[2017-10-20 19:49:48] nikic@php.net
I'm a bit skeptical here. I can understand handling EPERM, but EFAULT would generally imply an
error on *our* side, not something that should be silently ignored.
------------------------------------------------------------------------
[2017-10-20 19:43:16] kalle@php.net
Assigning to Sammy, our random_*() magic implementor guy :)
------------------------------------------------------------------------
[2017-10-20 09:44:27] martin dot zdrahal at s-team dot at
Description:
------------
When running php -r '\random_int(0,20);' on my QNAP NAS, PHP always returns an error. The
kernel on my NAS returns EPERM instead of ENOSYS, thus degrading to /dev/urandom does not happen.
This has been fixed in python a while back (https://bugs.python.org/issue27955, albeit it does not
catch EFAULT).
I suspect this behaviour exists in every PHP version that uses the getrandom() syscall
Test script:
---------------
\random_int(0,20);
Actual result:
--------------
PHP Fatal error: Uncaught Exception: Could not gather sufficient random data in Command line code:1
Stack trace:
#0 Command line code(1): random_int(0, 20)
#1 {main}
thrown in Command line code on line 1
strace output:
getrandom(0xbde13510, 4, 0) = -1 EFAULT (Bad address)
brk(0xb6587000) = 0xb6587000
writev(2, [{iov_base="", iov_len=0}, {iov_base="PHP Fatal error: Uncaught
Excep"..., iov_len=206}], 2PHP Fatal error: Uncaught Exception: Could not gather sufficient
random data in Command line code:1
Stack trace:
#0 Command line code(1): random_int(0, 20)
#1 {main}
thrown in Command line code on line 1) = 206
writev(2, [{iov_base="\n", iov_len=1}, {iov_base=NULL, iov_len=0}], 2
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75409&edit=1