Bug #71087 [Opn->Fbk]: Phar - cannot use OpenSSL signatures with custom stub

From: Date: Wed, 27 Jan 2021 11:51:09 +0000
Subject: Bug #71087 [Opn->Fbk]: Phar - cannot use OpenSSL signatures with custom stub
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231793@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71087&edit=1 ID: 71087 Updated by: cmb@php.net Reported by: securtiy at paragonie dot com Summary: Phar - cannot use OpenSSL signatures with custom stub -Status: Open +Status: Feedback Type: Bug Package: PHAR related Operating System: Debian 8.1 Jessie with Dotdeb PHP Version: 5.6.16 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: I cannot reproduce this issue with PHP-7.4 on Windows. That operation should be allowed anyway, so either the bug has been fixed in the meantime, or there is some relevant difference in our environments, or maybe my reproduce script doesn't exactly reproduce your build script. So, if you still have this issue with any of the actively supported PHP versions[1], please provide a minimal self-contained test script. [1] <https://www.php.net/supported-versions.php> Previous Comments: ------------------------------------------------------------------------ [2015-12-10 21:58:36] security at paragonie dot com In our use case, this resolved the problem... https://github.com/paragonie/php-encryption/commit/72418c9c9c4b244523da678a629227e16840de51 ...but that's a workaround, not a solution. ------------------------------------------------------------------------ [2015-12-10 21:49:59] securtiy at paragonie dot com Description: ------------ Is there any reason why we can't use Phar::setSignatureAlgorithm() after Phar::setStub()? https://github.com/defuse/php-encryption/pull/139 If there's a reason this shouldn't allowed, could the documentation please be updated to reflect this decision? If this is a bug, it's breaking our ability to publish signed a .phar for defuse/php-encryption Test script: --------------- https://raw.githubusercontent.com/paragonie/php-encryption/29dc5e866bb08dac38fef721f3356f2e2fea76c3/other/build_phar.php Expected result: ---------------- Silent success, but if I do this: $phar = new \Phar(dirname(__DIR__).'/dist/defuse-crypto.phar'); $signature = $phar->getSignature(); var_dump($signature); ...it shouldn't say its "hash_type" is "SHA-1" Actual result: -------------- PHP Fatal error: Uncaught exception 'PharException' with message 'unable to copy stub of old phar to new phar "/var/www/defuse/php-encryption/dist/defuse-crypto.phar"' in /var/www/defuse/php-encryption/other/build_phar.php:37 Stack trace: #0 /var/www/defuse/php-encryption/other/build_phar.php(37): Phar->setSignatureAlgorithm(16, '-----BEGIN PRIV...') #1 {main} thrown in /var/www/defuse/php-encryption/other/build_phar.php on line 37 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71087&edit=1

« previous php.bugs (#231793) next »