Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:110856 Return-Path: Delivered-To: mailing list internals@lists.php.net Received: (qmail 29350 invoked from network); 7 Jul 2020 02:07:55 -0000 Received: from unknown (HELO php-smtp4.php.net) (45.112.84.5) by pb1.pair.com with SMTP; 7 Jul 2020 02:07:55 -0000 Received: from php-smtp4.php.net (localhost [127.0.0.1]) by php-smtp4.php.net (Postfix) with ESMTP id 5D1D51804DE for ; Mon, 6 Jul 2020 17:58:28 -0700 (PDT) X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on php-smtp4.php.net X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_ENVFROM_END_DIGIT, FREEMAIL_FROM,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H2,SPF_HELO_PASS, SPF_PASS autolearn=no autolearn_force=no version=3.4.2 X-Spam-ASN: AS8075 40.80.0.0/12 X-Spam-Virus: No X-Envelope-From: Received: from NAM10-BN7-obe.outbound.protection.outlook.com (mail-bn7nam10olkn2021.outbound.protection.outlook.com [40.92.40.21]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by php-smtp4.php.net (Postfix) with ESMTPS for ; Mon, 6 Jul 2020 17:58:27 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=hwsf7aP+67YA4P6ypXmvPCJLX9NwdB66oTbtHO+N3r6loi9G2h3RPt2LiROm04Z64HSShvpz+AS605F6OJWdtQlYjczoWa3q1rZtjtaCBcIuVV4UyjjbJNvJd3JXT7Kyj8dxDO2crXXD5e3US17hlHvbHPllgVA+K/0W9X6/8pHKPWqJgUOmy87ZxcdB6xc8tSpbwf/fwI4lyulUOOEs9e7gurrgjmp8bgmx+8gjGs5bJcLoyeXnaimeIe0XDSlbMLASEj71syDpWXAl2iu7ctH2KSvSjN9RnBXb2YqZgx5W0lbLYw7DyjHCS7QSJEQtau0ymt+wcCDXCOIkG4E7ZA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=i6Iumb+XUSknYdK49peK+rGRwNUZaiJBhQ0nZEniPDQ=; b=QonJr+IL7pom/XMqMqY8/wWySXFOBbwR1/N+ewwT2ARXSPEkXwOkyUalEWC5WJAz8e02oYuo6MKicQyh/LlBrudhOiGaqP5XNBcAk2O6SoxVZ16oHahLh3PM1DF1g6exvb2O9BSjmPsn37sIuWjpl6npzrESuYJsbJsjHkZgKHy1VmBWjqZ/ltvCQndSQ8ypgKCNJEarSxItpVbD+MjLAvslls89AOyHX6ZaRR8ZbwKpKQ3EdLLAs2RRWJmfdYQoAYVWEdiZJbnfeo6K2+npEqllvRq8ln/Ic3GYmhOaC8m7fF884ZNV8eRV5+Z09bUHcin1TA3ZIqt8fyaagCXegg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=i6Iumb+XUSknYdK49peK+rGRwNUZaiJBhQ0nZEniPDQ=; b=S2MxVjKj0YEbE18U1pIZv1qPhMPCl/KlkMc00sg1Fp4UwCNZhI33PcF6+oPTYo/YsY91F5eu+uqglRnoBqVlh6/HHthmMp6x4WrbjvBhp2BA3oIN9lfVoA7pzZ9GJqZq1cuStknOTHY8MXeCMcovYJZ9RVFynm87qgJ5nsdnac4RtjQGxd3Wvt55aZNHwSD5JiPME3K7nbfJQwd/yzyLzzFq3/EkIdKUoMXPLZ2lZIqaM0kb2K1BcRMYhUheHY2I2XQZlkE729MnZpy+gcKxfnyyqybSixem9uZ7Q51o4mkq0b5Zcmie4F/JG6E33HjTTj0zBS/+ZaeuScvqnrhB9w== Received: from DM6NAM10FT054.eop-nam10.prod.protection.outlook.com (2a01:111:e400:7e86::4b) by DM6NAM10HT123.eop-nam10.prod.protection.outlook.com (2a01:111:e400:7e86::109) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3153.24; Tue, 7 Jul 2020 00:58:26 +0000 Received: from DM6PR07MB6618.namprd07.prod.outlook.com (2a01:111:e400:7e86::46) by DM6NAM10FT054.mail.protection.outlook.com (2a01:111:e400:7e86::423) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3153.24 via Frontend Transport; Tue, 7 Jul 2020 00:58:26 +0000 Received: from DM6PR07MB6618.namprd07.prod.outlook.com ([fe80::f0c8:f413:c7c1:e934]) by DM6PR07MB6618.namprd07.prod.outlook.com ([fe80::f0c8:f413:c7c1:e934%4]) with mapi id 15.20.3153.029; Tue, 7 Jul 2020 00:58:26 +0000 To: "internals@lists.php.net" CC: Bishop Bettini , Stanislav Malyshev Thread-Topic: Including "Disable the ability to use concrete types in PHAR metadata" in PHP 8.0? Thread-Index: AQHWU/GRw5eqUwR3jE+1bsRmt6W8gg== Date: Tue, 7 Jul 2020 00:58:25 +0000 Message-ID: Accept-Language: en-CA, en-US Content-Language: en-CA X-MS-Has-Attach: X-MS-TNEF-Correlator: x-incomingtopheadermarker: OriginalChecksum:C5AA506131907E6031EC5785BA55AD7CDD640B9605AE9F7E0781FEFC0A075A2A;UpperCasedChecksum:5C8BAC9513B43ABC361539177E053E2F07E7C7134FC243CC5B0E640D723A7EA7;SizeAsReceived:6978;Count:42 x-tmn: [AIluu1icZatl7mh0vK74wC/MZdoI3ndkVRdJZLAYADvuWU50NS+0pkU65ZavwdlJ] x-ms-publictraffictype: Email x-incomingheadercount: 42 x-eopattributedmessage: 0 x-ms-office365-filtering-correlation-id: d4a6a6f6-ad0d-470c-47d6-08d82210dae3 x-ms-traffictypediagnostic: DM6NAM10HT123: x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: hX4BO+crmCn7MU5UUL6+sI4jAXITxrmKa/N44hAc5mHb0FS+ZaprPQbLmgvc3umOlUSv4IZp6fo0JH+NJEtN31OhCVf78ryIlYgNrpA3uYiRNbDof0Mym0ow8VFzG8s2Tqjve9trcfoZhtrUDmxzGpLDzAgLKYh8n9/9eGx0tSw5MSKrM9k8lhGjB5Mk2NyEp8cdTZBY578oaI4HZkzNVOqgRt2OyxGE+JVDpOZ1Zgy+h3IzBupV3IVVbdW7afur x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:0;SRV:;IPV:NLI;SFV:NSPM;H:DM6PR07MB6618.namprd07.prod.outlook.com;PTR:;CAT:NONE;SFTY:;SFS:;DIR:OUT;SFP:1901; x-ms-exchange-antispam-messagedata: osSukbbLD2ka2iyzMc1C512bUyoCxteErYL6c89qGnCaU0RaegALwTNYOwZC7OrEt1r2DR5FKngw+p8veNv9eNFEriE5GVqKue5Pn5C1khJm0B0JF17BkyNZjLNv9PFtpIPLjbAQCnUpraPqrfALhPAMd0whKULd8WU38CCHAT9qe1Pn+MgLXBvU4x3sl3ym/EzsT05OfKQIsD2ysnGJwA== x-ms-exchange-transport-forked: True Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: hotmail.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-AuthSource: DM6NAM10FT054.eop-nam10.prod.protection.outlook.com X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-Network-Message-Id: d4a6a6f6-ad0d-470c-47d6-08d82210dae3 X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Jul 2020 00:58:25.9334 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Internet X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6NAM10HT123 Subject: Including "Disable the ability to use concrete types in PHAR metadata" in PHP 8.0? From: tysonandre775@hotmail.com (tyson andre) Hi internals,=0A= =0A= https://bugs.php.net/bug.php?id=3D76774 has been open since 2018-08-21.=0A= =0A= That ticket proposes the following:=0A= =0A= > I propose that we disable the ability to have concrete types included in = the serialized metadata by=0A= > providing an empty classlist to the unserialize call in the PHAR package.= =0A= > This will support the real cases we see in the wild of metadata usage whi= ch is only array key values.=0A= =0A= A major change such as PHP 8.0 seems like a good time to disable this.=0A= (but it seems safe enough for any minor version)=0A= =0A= Various blog posts have been written explaining the resulting vulnerabiliti= es,=0A= such as https://www.ixiacom.com/company/blog/exploiting-php-phar-deserializ= ation-vulnerabilities-part-1 =0A= =0A= This change was previously proposed in https://externals.io/message/105271#= 105303=0A= =0A= > Bishop Bettini wrote,=0A= >=0A= > I agree that $allowed_classes is a partial fix.=0A= > But is it not better to incrementally add defensive layers?=0A= >=0A= > I'll get to the immediate mitigation after I finish my phar fuzzing work,= =0A= > unless somebody beats me to it.=0A= =0A= I'm in favor of adding the defensive layer, and could probably implement th= e immediate mitigation if needed.=0A= =0A= Thoughts on whether this needs an RFC? Has anything changed since that emai= l thread? There seemed to be some debate over implementation details, but m= ost responses considered the existing unserialization behavior problematic.= =0A= =0A= - If it did, this may need to start less than two weeks after finishing an = RFC, due to the feature freeze in august 8th.=0A= =0A= I assume the limitation of not allowing any objects (i.e. $allowed_classes= =3D[]) for metadata would consistently affect getMetadata() and anything us= ing the phar stream wrapper for a phar file.=0A= Emitting an E_WARNING may be helpful but not absolutely necessary if an obj= ect is seen anywhere in the data passed to Phar->setMetadata().=0A= =0A= Thanks,=0A= - Tyson=