Bug #81491 [NEW]: Incorrectly using libsodium for argon2 hashing
| From: | dpock at liquidweb dot com | Date: | Thu, 30 Sep 2021 17:32:52 +0000 |
| Subject: | Bug #81491 [NEW]: Incorrectly using libsodium for argon2 hashing | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-236946@lists.php.net to get a copy of this message | ||
From: dpock at liquidweb dot com
Operating system:
PHP version: 8.1Git-2021-09-30 (Git)
Package: *Compile Issues
Bug Type: Bug
Bug description:Incorrectly using libsodium for argon2 hashing
Description:
------------
It appears that PHP-8.1 branch is no longer compiling libargon2 support
correctly. The effect of this vary depending on if libsodium is present
too.
When libsodium is present, the issue is observed are:
* Cannot use threads option when hashing with argon2,
* PASSWORD_ARGON2_PROVIDER reports as 'sodium'
When libsodium is not present, the issue observed is:
* Error stating argon2 is not supported
---
Note: Left OS blank as this affects my Mac, as well as linux based
GitHub runners.
---
I have 'confirmed' this bug by compiling PHP 8.0 and PHP 8.1 using the
same settings. When using PHP 8.0 w/o sodium I can still use argon2, and
similarly the threads option works when hashing.
I've also made a "PR" that confirms PHP 8.1 works when I revert a commit
to load argon2 via
pkg-config rather than config flags. This PR is
here: https://github.com/php/php-src/pull/7538
Test script:
---------------
This bug was initially found by Dries Vints via failing CI tests here:
https://github.com/laravel/framework/runs/3599702797#step:8:126
He was observing the issue with "threads" value greater than 1 causing
an error. This is behavior you'd only expect if PHP were compiled with
ONLY libsodium. However the GitHub runner's in use should be compiling
with BOTH libsodium and libargon2. We can be confident they are
compiling in this manner as PHP 8.0 runners (from the same source) are
working correctly.
Expected result:
----------------
PHP should know it has access to both libsodium and libargon2 when
compiled in this manner.
As such, when PHP compiles with both libs, we should see:
* PASSWORD_ARGON2_PROVIDER should be 'standard', and
* password_hash should accept threads > 1 when using argon2.
--
Edit bug report at https://bugs.php.net/bug.php?id=81491&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=81491&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=81491&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=81491&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=81491&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=81491&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=81491&r=support
Expected behavior: https://bugs.php.net/fix.php?id=81491&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=81491&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=81491&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=81491&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=81491&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=81491&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=81491&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=81491&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=81491&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=81491&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=81491&r=mysqlcfg