Bug #81491 [NEW]: Incorrectly using libsodium for argon2 hashing

From: Date: Thu, 30 Sep 2021 17:32:52 +0000
Subject: Bug #81491 [NEW]: Incorrectly using libsodium for argon2 hashing
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-236946@lists.php.net to get a copy of this message
From: dpock at liquidweb dot com Operating system: PHP version: 8.1Git-2021-09-30 (Git) Package: *Compile Issues Bug Type: Bug Bug description:Incorrectly using libsodium for argon2 hashing Description: ------------ It appears that PHP-8.1 branch is no longer compiling libargon2 support correctly. The effect of this vary depending on if libsodium is present too. When libsodium is present, the issue is observed are: * Cannot use threads option when hashing with argon2, * PASSWORD_ARGON2_PROVIDER reports as 'sodium' When libsodium is not present, the issue observed is: * Error stating argon2 is not supported --- Note: Left OS blank as this affects my Mac, as well as linux based GitHub runners. --- I have 'confirmed' this bug by compiling PHP 8.0 and PHP 8.1 using the same settings. When using PHP 8.0 w/o sodium I can still use argon2, and similarly the threads option works when hashing. I've also made a "PR" that confirms PHP 8.1 works when I revert a commit to load argon2 via pkg-config rather than config flags. This PR is here: https://github.com/php/php-src/pull/7538 Test script: --------------- This bug was initially found by Dries Vints via failing CI tests here: https://github.com/laravel/framework/runs/3599702797#step:8:126 He was observing the issue with "threads" value greater than 1 causing an error. This is behavior you'd only expect if PHP were compiled with ONLY libsodium. However the GitHub runner's in use should be compiling with BOTH libsodium and libargon2. We can be confident they are compiling in this manner as PHP 8.0 runners (from the same source) are working correctly. Expected result: ---------------- PHP should know it has access to both libsodium and libargon2 when compiled in this manner. As such, when PHP compiles with both libs, we should see: * PASSWORD_ARGON2_PROVIDER should be 'standard', and * password_hash should accept threads > 1 when using argon2. -- Edit bug report at https://bugs.php.net/bug.php?id=81491&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=81491&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=81491&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=81491&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=81491&r=needscript Try newer version: https://bugs.php.net/fix.php?id=81491&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=81491&r=support Expected behavior: https://bugs.php.net/fix.php?id=81491&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=81491&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=81491&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=81491&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=81491&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=81491&r=dst IIS Stability: https://bugs.php.net/fix.php?id=81491&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=81491&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=81491&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=81491&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=81491&r=mysqlcfg

« previous php.bugs (#236946) next »