[php-src] PR #24182: ext/sodium: revert addition of extendable output functions
| From: | DanielEScherzer | Date: | Wed, 07 Oct 2026 21:00:57 +0000 |
| Subject: | [php-src] PR #24182: ext/sodium: revert addition of extendable output functions | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39243@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24182
Author: DanielEScherzer
The extendable output functions treated the state as a string, rather than an opaque object, and
only validated the lengths of the strings before converting them to the underlying libsodium
objects. Thus, incorrect state values could be used to trigger out of bounds reads or updates.
The following constants are removed:
-
SODIUM_CRYPTO_XOF_SHAKE128_BLOCKBYTES
- SODIUM_CRYPTO_XOF_SHAKE128_STATEBYTES
- SODIUM_CRYPTO_XOF_SHAKE256_BLOCKBYTES
- SODIUM_CRYPTO_XOF_SHAKE256_STATEBYTES
- SODIUM_CRYPTO_XOF_TURBOSHAKE128_BLOCKBYTES
- SODIUM_CRYPTO_XOF_TURBOSHAKE128_STATEBYTES
- SODIUM_CRYPTO_XOF_TURBOSHAKE256_BLOCKBYTES
- SODIUM_CRYPTO_XOF_TURBOSHAKE256_STATEBYTES
The following functions are removed:
- sodium_crypto_xof_shake128()
- sodium_crypto_xof_shake128_init()
- sodium_crypto_xof_shake128_update()
- sodium_crypto_xof_shake128_squeeze()
- sodium_crypto_xof_shake256()
- sodium_crypto_xof_shake256_init()
- sodium_crypto_xof_shake256_update()
- sodium_crypto_xof_shake256_squeeze()
- sodium_crypto_xof_turboshake128()
- sodium_crypto_xof_turboshake128_init()
- sodium_crypto_xof_turboshake128_update()
- sodium_crypto_xof_turboshake128_squeeze()
- sodium_crypto_xof_turboshake256()
- sodium_crypto_xof_turboshake256_init()
- sodium_crypto_xof_turboshake256_update()
- sodium_crypto_xof_turboshake256_squeeze()