Bug #75409 [Asn->Csd]: accept EFAULT in addition to ENOSYS as indicator that getrandom() is missing
Edit report at https://bugs.php.net/bug.php?id=75409&edit=1
ID: 75409
Updated by: krakjoe@php.net
Reported by: martin dot zdrahal at s-team dot at
Summary: accept EFAULT in addition to ENOSYS as indicator
that getrandom() is missing
-Status: Assigned
+Status: Closed
Type: Bug
Package: *Encryption and hash functions
Operating System: Linux
PHP Version: 7.1.10
Assigned To: sarciszewski
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of scott@paragonie.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=269d1601596341f574ff6c875a826ce2b671f1f0
Log: Fix bug #75409
Previous Comments:
------------------------------------------------------------------------
[2017-11-22 03:03:10] security at paragonie dot com
This should fix this issue. I hope the fix can be backported into 7.0, 7.1, and 7.2 for the next,
next, and first (respectively) releases.
https://github.com/php/php-src/pull/2932/commits/9aadac9778096290c6d85946fabbe5c883a9f723
------------------------------------------------------------------------
[2017-10-21 18:17:24] security at paragonie dot com
After checking with Frank Denis, all responses except EINTR or EAGAIN should fallback to
/dev/urandom. https://twitter.com/jedisct1/status/921801560006504450
So, let's make sure that is happening.
------------------------------------------------------------------------
[2017-10-21 18:11:15] security at paragonie dot com
EPERM is not supposed to be returned by this system call. That means that QNAP is behaving weirdly
and the problem should be fixed on their side.
If a QNAP-specific workaround is desired, first we will need to ensure it's only ever employed
on QNAP kernels. Is there a way to detect them at compile-time?
------------------------------------------------------------------------
[2017-10-20 19:49:48] nikic@php.net
I'm a bit skeptical here. I can understand handling EPERM, but EFAULT would generally imply an
error on *our* side, not something that should be silently ignored.
------------------------------------------------------------------------
[2017-10-20 19:43:16] kalle@php.net
Assigning to Sammy, our random_*() magic implementor guy :)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75409
--
Edit this bug report at https://bugs.php.net/bug.php?id=75409&edit=1
Thread (7 messages)