Skip to content

Commit c311ab7

Browse files
committed
Mark parameter in ext/openssl as sensitive
1 parent e85b17b commit c311ab7

File tree

3 files changed

+121
-12
lines changed

3 files changed

+121
-12
lines changed

ext/openssl/openssl.c

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,7 @@
2727
#include "php.h"
2828
#include "php_ini.h"
2929
#include "php_openssl.h"
30+
#include "zend_attributes.h"
3031
#include "zend_exceptions.h"
3132

3233
/* PHP Includes */
@@ -1392,6 +1393,8 @@ PHP_MINIT_FUNCTION(openssl)
13921393

13931394
REGISTER_INI_ENTRIES();
13941395

1396+
register_openssl_symbols(module_number);
1397+
13951398
return SUCCESS;
13961399
}
13971400
/* }}} */

ext/openssl/openssl.stub.php

Lines changed: 74 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,10 @@ function openssl_x509_export(OpenSSLCertificate|string $certificate, &$output, b
3333

3434
function openssl_x509_fingerprint(OpenSSLCertificate|string $certificate, string $digest_algo = "sha1", bool $binary = false): string|false {}
3535

36-
/** @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key */
36+
/**
37+
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
38+
* @sensitive-param $private_key
39+
*/
3740
function openssl_x509_check_private_key(OpenSSLCertificate|string $certificate, $private_key): bool {}
3841

3942
/** @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $public_key */
@@ -52,27 +55,42 @@ function openssl_x509_read(OpenSSLCertificate|string $certificate): OpenSSLCerti
5255
/** @deprecated */
5356
function openssl_x509_free(OpenSSLCertificate $certificate): void {}
5457

55-
/** @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key */
58+
/**
59+
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
60+
* @sensitive-param $private_key
61+
* @sensitive-param $passphrase
62+
*/
5663
function openssl_pkcs12_export_to_file(OpenSSLCertificate|string $certificate, string $output_filename, $private_key, string $passphrase, array $options = []): bool {}
5764

5865
/**
5966
* @param string $output
6067
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
68+
* @sensitive-param $private_key
69+
* @sensitive-param $passphrase
6170
*/
6271
function openssl_pkcs12_export(OpenSSLCertificate|string $certificate, &$output, $private_key, string $passphrase, array $options = []): bool {}
6372

64-
/** @param array $certificates */
73+
/**
74+
* @param array $certificates
75+
* @sensitive-param $passphrase
76+
*/
6577
function openssl_pkcs12_read(string $pkcs12, &$certificates, string $passphrase): bool {}
6678

6779
function openssl_csr_export_to_file(OpenSSLCertificateSigningRequest|string $csr, string $output_filename, bool $no_text = true): bool {}
6880

6981
/** @param string $output */
7082
function openssl_csr_export(OpenSSLCertificateSigningRequest|string $csr, &$output, bool $no_text = true): bool {}
7183

72-
/** @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key */
84+
/**
85+
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
86+
* @sensitive-param $private_key
87+
*/
7388
function openssl_csr_sign(OpenSSLCertificateSigningRequest|string $csr, OpenSSLCertificate|string|null $ca_certificate, $private_key, int $days, ?array $options = null, int $serial = 0): OpenSSLCertificate|false {}
7489

75-
/** @param OpenSSLAsymmetricKey $private_key */
90+
/**
91+
* @param OpenSSLAsymmetricKey $private_key
92+
* @sensitive-param $private_key
93+
*/
7694
function openssl_csr_new(array $distinguished_names, &$private_key, ?array $options = null, ?array $extra_attributes = null): OpenSSLCertificateSigningRequest|false {}
7795

7896
/**
@@ -85,12 +103,18 @@ function openssl_csr_get_public_key(OpenSSLCertificateSigningRequest|string $csr
85103

86104
function openssl_pkey_new(?array $options = null): OpenSSLAsymmetricKey|false {}
87105

88-
/** @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $key */
106+
/**
107+
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $key
108+
* @sensitive-param $key
109+
* @sensitive-param $passphrase
110+
*/
89111
function openssl_pkey_export_to_file($key, string $output_filename, ?string $passphrase = null, ?array $options = null): bool {}
90112

91113
/**
92114
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $key
93115
* @param string $output
116+
* @sensitive-param $key
117+
* @sensitive-param $passphrase
94118
*/
95119
function openssl_pkey_export($key, &$output, ?string $passphrase = null, ?array $options = null): bool {}
96120

@@ -103,7 +127,9 @@ function openssl_pkey_get_public($public_key): OpenSSLAsymmetricKey|false {}
103127
*/
104128
function openssl_get_publickey($public_key): OpenSSLAsymmetricKey|false {}
105129

106-
/** @deprecated */
130+
/**
131+
* @deprecated
132+
*/
107133
function openssl_pkey_free(OpenSSLAsymmetricKey $key): void {}
108134

109135
/**
@@ -112,11 +138,17 @@ function openssl_pkey_free(OpenSSLAsymmetricKey $key): void {}
112138
*/
113139
function openssl_free_key(OpenSSLAsymmetricKey $key): void {}
114140

115-
/** @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key */
141+
/**
142+
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
143+
* @sensitive-param $private_key
144+
* @sensitive-param $passphrase
145+
*/
116146
function openssl_pkey_get_private($private_key, ?string $passphrase = null): OpenSSLAsymmetricKey|false {}
117147

118148
/**
119149
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
150+
* @sensitive-param $private_key
151+
* @sensitive-param $passphrase
120152
* @alias openssl_pkey_get_private
121153
*/
122154
function openssl_get_privatekey($private_key, ?string $passphrase = null): OpenSSLAsymmetricKey|false {}
@@ -127,19 +159,25 @@ function openssl_get_privatekey($private_key, ?string $passphrase = null): OpenS
127159
*/
128160
function openssl_pkey_get_details(OpenSSLAsymmetricKey $key): array|false {}
129161

162+
/** @sensitive-param $password */
130163
function openssl_pbkdf2(string $password, string $salt, int $key_length, int $iterations, string $digest_algo = "sha1"): string|false {}
131164

132165
function openssl_pkcs7_verify(string $input_filename, int $flags, ?string $signers_certificates_filename = null, array $ca_info = [], ?string $untrusted_certificates_filename = null, ?string $content = null, ?string $output_filename = null): bool|int {}
133166

134167
/** @param OpenSSLCertificate|array|string $certificate */
135168
function openssl_pkcs7_encrypt(string $input_filename, string $output_filename, $certificate, ?array $headers, int $flags = 0, int $cipher_algo = OPENSSL_CIPHER_AES_128_CBC): bool {}
136169

137-
/** @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key */
170+
/**
171+
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
172+
* @sensitive-param $private_key
173+
*/
138174
function openssl_pkcs7_sign(string $input_filename, string $output_filename, OpenSSLCertificate|string $certificate, $private_key, ?array $headers, int $flags = PKCS7_DETACHED, ?string $untrusted_certificates_filename = null): bool {}
139175

140176
/**
141177
* @param OpenSSLCertificate|string $certificate
142178
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string|null $private_key
179+
* @sensitive-param $certificate
180+
* @sensitive-param $private_key
143181
*/
144182
function openssl_pkcs7_decrypt(string $input_filename, string $output_filename, $certificate, $private_key = null): bool {}
145183

@@ -151,12 +189,17 @@ function openssl_cms_verify(string $input_filename, int $flags = 0, ?string $cer
151189
/** @param OpenSSLCertificate|array|string $certificate */
152190
function openssl_cms_encrypt(string $input_filename, string $output_filename, $certificate, ?array $headers, int $flags = 0, int $encoding = OPENSSL_ENCODING_SMIME, int $cipher_algo = OPENSSL_CIPHER_AES_128_CBC): bool {}
153191

154-
/** @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key */
192+
/**
193+
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
194+
* @sensitive-param $private_key
195+
*/
155196
function openssl_cms_sign(string $input_filename, string $output_filename, OpenSSLCertificate|string $certificate, $private_key, ?array $headers, int $flags = 0, int $encoding = OPENSSL_ENCODING_SMIME, ?string $untrusted_certificates_filename = null): bool {}
156197

157198
/**
158199
* @param OpenSSLCertificate|string $certificate
159200
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string|null $private_key
201+
* @sensitive-param $certificate
202+
* @sensitive-param $private_key
160203
*/
161204
function openssl_cms_decrypt(string $input_filename, string $output_filename, $certificate, $private_key = null, int $encoding = OPENSSL_ENCODING_SMIME): bool {}
162205

@@ -166,24 +209,30 @@ function openssl_cms_read(string $input_filename, &$certificates): bool {}
166209
/**
167210
* @param string $encrypted_data
168211
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
212+
* @sensitive-param $data
213+
* @sensitive-param $private_key
169214
*/
170215
function openssl_private_encrypt(string $data, &$encrypted_data, $private_key, int $padding = OPENSSL_PKCS1_PADDING): bool {}
171216

172217
/**
173218
* @param string $decrypted_data
174219
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
220+
* @sensitive-param $decrypted_data
221+
* @sensitive-param $private_key
175222
*/
176223
function openssl_private_decrypt(string $data, &$decrypted_data, $private_key, int $padding = OPENSSL_PKCS1_PADDING): bool {}
177224

178225
/**
179226
* @param string $encrypted_data
180227
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $public_key
228+
* @sensitive-param $data
181229
*/
182230
function openssl_public_encrypt(string $data, &$encrypted_data, $public_key, int $padding = OPENSSL_PKCS1_PADDING): bool {}
183231

184232
/**
185233
* @param string $decrypted_data
186234
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $public_key
235+
* @sensitive-param $decrypted_data
187236
*/
188237
function openssl_public_decrypt(string $data, &$decrypted_data, $public_key, int $padding = OPENSSL_PKCS1_PADDING): bool {}
189238

@@ -192,6 +241,7 @@ function openssl_error_string(): string|false {}
192241
/**
193242
* @param string $signature
194243
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
244+
* @sensitive-param $private_key
195245
*/
196246
function openssl_sign(string $data, &$signature, $private_key, string|int $algorithm = OPENSSL_ALGO_SHA1): bool {}
197247

@@ -202,12 +252,15 @@ function openssl_verify(string $data, string $signature, $public_key, string|int
202252
* @param string $sealed_data
203253
* @param array $encrypted_keys
204254
* @param string $iv
255+
* @sensitive-param $data
205256
*/
206257
function openssl_seal(string $data, &$sealed_data, &$encrypted_keys, array $public_key, string $cipher_algo, &$iv = null): int|false {}
207258

208259
/**
209260
* @param string $output
210261
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
262+
* @sensitive-param $output
263+
* @sensitive-param $private_key
211264
*/
212265
function openssl_open(string $data, &$output, string $encrypted_key, $private_key, string $cipher_algo, ?string $iv = null): bool {}
213266

@@ -233,24 +286,34 @@ function openssl_get_curve_names(): array|false {}
233286

234287
function openssl_digest(string $data, string $digest_algo, bool $binary = false): string|false {}
235288

236-
/** @param string $tag */
289+
/**
290+
* @param string $tag
291+
* @sensitive-param $data
292+
* @sensitive-param $passphrase
293+
*/
237294
function openssl_encrypt(string $data, string $cipher_algo, string $passphrase, int $options = 0, string $iv = "", &$tag = null, string $aad = "", int $tag_length = 16): string|false {}
238295

296+
/**
297+
* @sensitive-param $passphrase
298+
*/
239299
function openssl_decrypt(string $data, string $cipher_algo, string $passphrase, int $options = 0, string $iv = "", ?string $tag = null, string $aad = ""): string|false {}
240300

241301
function openssl_cipher_iv_length(string $cipher_algo): int|false {}
242302

303+
/** @sensitive-param $private_key */
243304
function openssl_dh_compute_key(string $public_key, OpenSSLAsymmetricKey $private_key): string|false {}
244305

245306
/**
246307
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $public_key
247308
* @param OpenSSLAsymmetricKey|OpenSSLCertificate|array|string $private_key
309+
* @sensitive-param $private_key
248310
*/
249311
function openssl_pkey_derive($public_key, $private_key, int $key_length = 0): string|false {}
250312

251313
/** @param bool $strong_result */
252314
function openssl_random_pseudo_bytes(int $length, &$strong_result = null): string {}
253315

316+
/** @sensitive-param $private_key */
254317
function openssl_spki_new(OpenSSLAsymmetricKey $private_key, string $challenge, int $digest_algo = OPENSSL_ALGO_MD5): string|false {}
255318

256319
function openssl_spki_verify(string $spki): bool {}

ext/openssl/openssl_arginfo.h

Lines changed: 44 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)