Req #80214 [Com]: random_bytes(): 0 random bytes should be a valid request
| From: | a at b dot c dot de | Date: | Thu, 29 Oct 2020 08:50:18 +0000 |
| Subject: | Req #80214 [Com]: random_bytes(): 0 random bytes should be a valid request | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229997@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80214&edit=1
ID: 80214
Comment by: a at b dot c dot de
Reported by: divinity76 at gmail dot com
Summary: random_bytes(): 0 random bytes should be a valid
request
Status: Open
Type: Feature/Change Request
Package: Unknown/Other Function
PHP Version: Next Minor Version
Block user comment: N
Private report: N
New Comment:
It may be as simple as tweaking the size check in PHP_FUNCTION(random_bytes) and the corresponding
error message. But that depends on whether all of the methods on all the platforms are as
accommodating as the Linux kernel syscall (as demonstrated above).
If any are stroppy, php_random_bytes() would have to wend around the problem areas. It's not
enough to just put a "if size is zero, return empty string" test at the top: for
consistency, the function should still abort if there is no adequate entropy source available (I can
think of at least three potential issues if php_random_bytes(0) always succeeded).
Previous Comments:
------------------------------------------------------------------------
[2020-10-15 10:22:50] divinity76 at gmail dot com
@rtrtrtrtrt
at least the Linux Kernel developers think it's ok to ask for 0 random bytes, when you ask the
linux kernel getrandom() api ( https://man7.org/linux/man-pages/man2/getrandom.2.html
) for 0 random, it will check that you're capable of generating random bytes, then.. generate 0
random bytes, and return the number of bytes it generated... 0, and not set any error notice
anywhere (not in the return value itself, and not in errno)
testing it:
hans@xDevAd:~/projects/misc$ cat ggg.cpp
#include <iostream>
#include <sys/random.h>
#include <errno.h>
#include <unistd.h>
#include <sys/syscall.h> /* For SYS_xxx definitions */
int main(){
std::string buf;
std::cout << "errno before: " << errno << std::endl;
const int flags = 0;
std::cout << "libc getrandom: " << getrandom((char*)buf.data(), buf.size(),
flags) << std::endl;
std::cout << "errno after: " << errno << std::endl;
std::cout << "syscall getrandom (practically bypassing libc): " <<
syscall(SYS_getrandom, (char*)buf.data(), buf.size(), flags) << std::endl;
std::cout << "errno after: " << errno << std::endl;
}
hans@xDevAd:~/projects/misc$ g++ -Wall -Wextra -Wpedantic -Werror ggg.cpp
hans@xDevAd:~/projects/misc$ ./a.out
errno before: 0
libc getrandom: 0
errno after: 0
syscall getrandom (practically bypassing libc): 0
errno after: 0
hans@xDevAd:~/projects/misc$
- if the linux kernel had a problem with any of this, one of the numbers should have been <0
------------------------------------------------------------------------
[2020-10-15 09:50:29] nikic@php.net
FWIW I agree that random_bytes(0) should be legal.
------------------------------------------------------------------------
[2020-10-15 09:32:05] rtrtrtrtrt at dfdfdfdf dot dfd
> it's ok to request a string to be repeated 0 times,
> but it's not ok to ask for 0 random bytes?
you still don#t get the difference of a random string operation and a function which is meant for
for cryptographic safe randomness meat for security relevant context
are you sure that you don't absue random_bytes() at all in your sue case which likely
don't need randomness in that quality
> is that the opinion of you guys?
yes
> or do you guys consider str_repeat() broken in this regard?
no or how is it a security context line random_bytes()?
------------------------------------------------------------------------
[2020-10-15 09:19:36] divinity76 at gmail dot com
let me get this straight guys,
requesting str_repeat("A",0) will give you an empty string, as one would expect (request:
repeat "A" 0 times)
requesting random_bytes(0) will give you an exception... (request: give me 0 random bytes)
and both of these make sense to you? it's ok to request a string to be repeated 0 times, but
it's not ok to ask for 0 random bytes? is that the opinion of you guys? or do you guys consider
str_repeat() broken in this regard?
------------------------------------------------------------------------
[2020-10-15 03:32:54] a at b dot c dot de
Scenario: I have a block of bytes that I want to pad to a specific length by appending some
randomness (after embedding the message length) because the length of the message would otherwise be
a potential information leak.
The most straightforward way of doing it would be " . random_bytes(strlen($message) %
BLOCK_SIZE)".
To claim that random_bytes(0) should be special-cased is like claiming if() statements should be
written to protect sort() from an empty array argument.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80214
--
Edit this bug report at https://bugs.php.net/bug.php?id=80214&edit=1