Bug #77646 [Opn]: sodium_crypto_sign_detached() does not zero-terminate signature

From: Date: Thu, 21 Feb 2019 13:19:28 +0000
Subject: Bug #77646 [Opn]: sodium_crypto_sign_detached() does not zero-terminate signature
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219680@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77646&edit=1 ID: 77646 User updated by: thomaswouters+bugs dot php dot net at gmail dot com Reported by: thomaswouters+bugs dot php dot net at gmail dot com Summary: sodium_crypto_sign_detached() does not zero-terminate signature Status: Open Type: Bug Package: *Encryption and hash functions Operating System: Linux PHP Version: 7.3.2 Block user comment: N Private report: N New Comment: Test script should have been: <?php $alice_sk = base64_decode('NNiJwjbkZ/5zUEj8KW8HENU34RVZ22XmvqFLj2xhlUa6ht6V6u/t97mfF6hW8UQgEvOdA/JSz/grVFVxoM5Y5g=='); $message = 'This is a test message.'; $signature = sodium_crypto_sign_detached($message, $alice_sk); var_dump(base64_encode($signature)); Previous Comments: ------------------------------------------------------------------------ [2019-02-21 13:15:45] thomaswouters+bugs dot php dot net at gmail dot com Description: ------------ sodium_crypto_sign_detached() behaves irregular on a legacy system (I guess it might be related to an old gcc version - 4.7.2). Using the function sodium_crypto_sign_detached() in php-fpm resulted in a fatal error: PHP Fatal error: Uncaught SodiumException: secret key size should be SODIUM_CRYPTO_SIGN_SECRETKEYBYTES bytes in /tmp/sodium.php I was able to reproduce it with php command line on older systems by enabling opcache (-d "opcache.enable_cli=On") but not on Debian stretch, buster, Archlinux or Alpine. Toggling opcache in php-fpm did not make a difference and the exception was thrown regardless. When built with --enable-debug PHP throws an assertion error on ZEND_ASSERT(ZSTR_VAL(signature)[signature_real_len] == 0);: Warning: String is not zero-terminated (*garbage*) in Unknown on line 0 After taking a look at sodium_crypto_sign() I've noticed that there's some extra code to zero-terminate the signed message: PHP_SODIUM_ZSTR_TRUNCATE(msg_signed, (size_t) msg_signed_real_len); ZSTR_VAL(msg_signed)[msg_signed_real_len] = 0; I've replaced the assertion in sodium_crypto_sign_detached() with the following code and was unable to reproduce the SodiumException both on cli as php-fpm: PHP_SODIUM_ZSTR_TRUNCATE(signature, (size_t) signature_real_len); ZSTR_VAL(signature)[signature_real_len] = 0; Test script: --------------- <?php $alice_sk = base64_decode('NNiJwjbkZ/5zUEj8KW8HENU34RVZ22XmvqFLj2xhlUa6ht6V6u/t97mfF6hW8UQgEvOdA/JSz/grVFVxoM5Y5g=='); $message = 'This is a test message.'; $signature = sodium_crypto_sign_detached($message, $alice_sk); var_dump($signature); Expected result: ---------------- string(88) "Fb5LHxwnrUnmNzdc01sEBJpgi+milnYjWagSiS4WfCmdjC4XOHIF753unPMSLAmmYQqjhS3raQfHs/02QQGoDA==" Actual result: -------------- Fatal error: Uncaught SodiumException: secret key size should be SODIUM_CRYPTO_SIGN_SECRETKEYBYTES bytes in /tmp/sodium.php:4 Stack trace: #0 /tmp/sodium.php(4): sodium_crypto_sign_detached() #1 {main} thrown in /tmp/sodium.php on line 4 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77646&edit=1

« previous php.bugs (#219680) next »