mcrypt.c 41 KB


  1. /*
  2. +----------------------------------------------------------------------+
  3. | PHP Version 5 |
  4. +----------------------------------------------------------------------+
  5. | Copyright (c) 1997-2016 The PHP Group |
  6. +----------------------------------------------------------------------+
  7. | This source file is subject to version 3.01 of the PHP license, |
  8. | that is bundled with this package in the file LICENSE, and is |
  9. | available through the world-wide-web at the following url: |
  10. | http://www.php.net/license/3_01.txt |
  11. | If you did not receive a copy of the PHP license and are unable to |
  12. | obtain it through the world-wide-web, please send a note to |
  13. | license@php.net so we can mail you a copy immediately. |
  14. +----------------------------------------------------------------------+
  15. | Authors: Sascha Schumann <sascha@schumann.cx> |
  16. | Derick Rethans <derick@derickrethans.nl> |
  17. +----------------------------------------------------------------------+
  18. */
  19. /* $Id$ */
  20. #ifdef HAVE_CONFIG_H
  21. #include "config.h"
  22. #endif
  23. #include "php.h"
  24. #if HAVE_LIBMCRYPT
  25. #if PHP_WIN32
  26. # include "win32/winutil.h"
  27. #endif
  28. #include "php_mcrypt.h"
  29. #include "fcntl.h"
  30. #define NON_FREE
  31. #define MCRYPT2
  32. #include "mcrypt.h"
  33. #include "php_ini.h"
  34. #include "php_globals.h"
  35. #include "ext/standard/info.h"
  36. #include "ext/standard/php_rand.h"
  37. #include "ext/standard/php_smart_str.h"
  38. #include "php_mcrypt_filter.h"
  39. static int le_mcrypt;
  40. typedef struct _php_mcrypt {
  41. MCRYPT td;
  42. zend_bool init;
  43. } php_mcrypt;
  44. /* {{{ arginfo */
  45. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_module_open, 0, 0, 4)
  46. ZEND_ARG_INFO(0, cipher)
  47. ZEND_ARG_INFO(0, cipher_directory)
  48. ZEND_ARG_INFO(0, mode)
  49. ZEND_ARG_INFO(0, mode_directory)
  50. ZEND_END_ARG_INFO()
  51. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_generic_init, 0, 0, 3)
  52. ZEND_ARG_INFO(0, td)
  53. ZEND_ARG_INFO(0, key)
  54. ZEND_ARG_INFO(0, iv)
  55. ZEND_END_ARG_INFO()
  56. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_generic, 0, 0, 2)
  57. ZEND_ARG_INFO(0, td)
  58. ZEND_ARG_INFO(0, data)
  59. ZEND_END_ARG_INFO()
  60. ZEND_BEGIN_ARG_INFO_EX(arginfo_mdecrypt_generic, 0, 0, 2)
  61. ZEND_ARG_INFO(0, td)
  62. ZEND_ARG_INFO(0, data)
  63. ZEND_END_ARG_INFO()
  64. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_enc_get_supported_key_sizes, 0, 0, 1)
  65. ZEND_ARG_INFO(0, td)
  66. ZEND_END_ARG_INFO()
  67. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_enc_self_test, 0, 0, 1)
  68. ZEND_ARG_INFO(0, td)
  69. ZEND_END_ARG_INFO()
  70. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_module_close, 0, 0, 1)
  71. ZEND_ARG_INFO(0, td)
  72. ZEND_END_ARG_INFO()
  73. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_generic_deinit, 0, 0, 1)
  74. ZEND_ARG_INFO(0, td)
  75. ZEND_END_ARG_INFO()
  76. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_enc_is_block_algorithm_mode, 0, 0, 1)
  77. ZEND_ARG_INFO(0, td)
  78. ZEND_END_ARG_INFO()
  79. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_enc_is_block_algorithm, 0, 0, 1)
  80. ZEND_ARG_INFO(0, td)
  81. ZEND_END_ARG_INFO()
  82. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_enc_is_block_mode, 0, 0, 1)
  83. ZEND_ARG_INFO(0, td)
  84. ZEND_END_ARG_INFO()
  85. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_enc_get_block_size, 0, 0, 1)
  86. ZEND_ARG_INFO(0, td)
  87. ZEND_END_ARG_INFO()
  88. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_enc_get_key_size, 0, 0, 1)
  89. ZEND_ARG_INFO(0, td)
  90. ZEND_END_ARG_INFO()
  91. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_enc_get_iv_size, 0, 0, 1)
  92. ZEND_ARG_INFO(0, td)
  93. ZEND_END_ARG_INFO()
  94. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_enc_get_algorithms_name, 0, 0, 1)
  95. ZEND_ARG_INFO(0, td)
  96. ZEND_END_ARG_INFO()
  97. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_enc_get_modes_name, 0, 0, 1)
  98. ZEND_ARG_INFO(0, td)
  99. ZEND_END_ARG_INFO()
  100. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_module_self_test, 0, 0, 1)
  101. ZEND_ARG_INFO(0, algorithm)
  102. ZEND_ARG_INFO(0, lib_dir)
  103. ZEND_END_ARG_INFO()
  104. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_module_is_block_algorithm_mode, 0, 0, 1)
  105. ZEND_ARG_INFO(0, mode)
  106. ZEND_ARG_INFO(0, lib_dir)
  107. ZEND_END_ARG_INFO()
  108. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_module_is_block_algorithm, 0, 0, 1)
  109. ZEND_ARG_INFO(0, algorithm)
  110. ZEND_ARG_INFO(0, lib_dir)
  111. ZEND_END_ARG_INFO()
  112. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_module_is_block_mode, 0, 0, 1)
  113. ZEND_ARG_INFO(0, mode)
  114. ZEND_ARG_INFO(0, lib_dir)
  115. ZEND_END_ARG_INFO()
  116. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_module_get_algo_block_size, 0, 0, 1)
  117. ZEND_ARG_INFO(0, algorithm)
  118. ZEND_ARG_INFO(0, lib_dir)
  119. ZEND_END_ARG_INFO()
  120. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_module_get_algo_key_size, 0, 0, 1)
  121. ZEND_ARG_INFO(0, algorithm)
  122. ZEND_ARG_INFO(0, lib_dir)
  123. ZEND_END_ARG_INFO()
  124. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_module_get_supported_key_sizes, 0, 0, 1)
  125. ZEND_ARG_INFO(0, algorithm)
  126. ZEND_ARG_INFO(0, lib_dir)
  127. ZEND_END_ARG_INFO()
  128. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_list_algorithms, 0, 0, 0)
  129. ZEND_ARG_INFO(0, lib_dir)
  130. ZEND_END_ARG_INFO()
  131. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_list_modes, 0, 0, 0)
  132. ZEND_ARG_INFO(0, lib_dir)
  133. ZEND_END_ARG_INFO()
  134. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_get_key_size, 0, 0, 2)
  135. ZEND_ARG_INFO(0, cipher)
  136. ZEND_ARG_INFO(0, module)
  137. ZEND_END_ARG_INFO()
  138. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_get_block_size, 0, 0, 2)
  139. ZEND_ARG_INFO(0, cipher)
  140. ZEND_ARG_INFO(0, module)
  141. ZEND_END_ARG_INFO()
  142. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_get_iv_size, 0, 0, 2)
  143. ZEND_ARG_INFO(0, cipher)
  144. ZEND_ARG_INFO(0, module)
  145. ZEND_END_ARG_INFO()
  146. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_get_cipher_name, 0, 0, 1)
  147. ZEND_ARG_INFO(0, cipher)
  148. ZEND_END_ARG_INFO()
  149. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_encrypt, 0, 0, 5)
  150. ZEND_ARG_INFO(0, cipher)
  151. ZEND_ARG_INFO(0, key)
  152. ZEND_ARG_INFO(0, data)
  153. ZEND_ARG_INFO(0, mode)
  154. ZEND_ARG_INFO(0, iv)
  155. ZEND_END_ARG_INFO()
  156. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_decrypt, 0, 0, 5)
  157. ZEND_ARG_INFO(0, cipher)
  158. ZEND_ARG_INFO(0, key)
  159. ZEND_ARG_INFO(0, data)
  160. ZEND_ARG_INFO(0, mode)
  161. ZEND_ARG_INFO(0, iv)
  162. ZEND_END_ARG_INFO()
  163. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_ecb, 0, 0, 5)
  164. ZEND_ARG_INFO(0, cipher)
  165. ZEND_ARG_INFO(0, key)
  166. ZEND_ARG_INFO(0, data)
  167. ZEND_ARG_INFO(0, mode)
  168. ZEND_ARG_INFO(0, iv)
  169. ZEND_END_ARG_INFO()
  170. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_cbc, 0, 0, 5)
  171. ZEND_ARG_INFO(0, cipher)
  172. ZEND_ARG_INFO(0, key)
  173. ZEND_ARG_INFO(0, data)
  174. ZEND_ARG_INFO(0, mode)
  175. ZEND_ARG_INFO(0, iv)
  176. ZEND_END_ARG_INFO()
  177. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_cfb, 0, 0, 5)
  178. ZEND_ARG_INFO(0, cipher)
  179. ZEND_ARG_INFO(0, key)
  180. ZEND_ARG_INFO(0, data)
  181. ZEND_ARG_INFO(0, mode)
  182. ZEND_ARG_INFO(0, iv)
  183. ZEND_END_ARG_INFO()
  184. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_ofb, 0, 0, 5)
  185. ZEND_ARG_INFO(0, cipher)
  186. ZEND_ARG_INFO(0, key)
  187. ZEND_ARG_INFO(0, data)
  188. ZEND_ARG_INFO(0, mode)
  189. ZEND_ARG_INFO(0, iv)
  190. ZEND_END_ARG_INFO()
  191. ZEND_BEGIN_ARG_INFO_EX(arginfo_mcrypt_create_iv, 0, 0, 1)
  192. ZEND_ARG_INFO(0, size)
  193. ZEND_ARG_INFO(0, source)
  194. ZEND_END_ARG_INFO()
  195. /* }}} */
  196. const zend_function_entry mcrypt_functions[] = { /* {{{ */
  197. PHP_DEP_FE(mcrypt_ecb, arginfo_mcrypt_ecb)
  198. PHP_DEP_FE(mcrypt_cbc, arginfo_mcrypt_cbc)
  199. PHP_DEP_FE(mcrypt_cfb, arginfo_mcrypt_cfb)
  200. PHP_DEP_FE(mcrypt_ofb, arginfo_mcrypt_ofb)
  201. PHP_FE(mcrypt_get_key_size, arginfo_mcrypt_get_key_size)
  202. PHP_FE(mcrypt_get_block_size, arginfo_mcrypt_get_block_size)
  203. PHP_FE(mcrypt_get_cipher_name, arginfo_mcrypt_get_cipher_name)
  204. PHP_FE(mcrypt_create_iv, arginfo_mcrypt_create_iv)
  205. PHP_FE(mcrypt_list_algorithms, arginfo_mcrypt_list_algorithms)
  206. PHP_FE(mcrypt_list_modes, arginfo_mcrypt_list_modes)
  207. PHP_FE(mcrypt_get_iv_size, arginfo_mcrypt_get_iv_size)
  208. PHP_FE(mcrypt_encrypt, arginfo_mcrypt_encrypt)
  209. PHP_FE(mcrypt_decrypt, arginfo_mcrypt_decrypt)
  210. PHP_FE(mcrypt_module_open, arginfo_mcrypt_module_open)
  211. PHP_FE(mcrypt_generic_init, arginfo_mcrypt_generic_init)
  212. PHP_FE(mcrypt_generic, arginfo_mcrypt_generic)
  213. PHP_FE(mdecrypt_generic, arginfo_mdecrypt_generic)
  214. PHP_DEP_FALIAS(mcrypt_generic_end, mcrypt_generic_deinit, arginfo_mcrypt_generic_deinit)
  215. PHP_FE(mcrypt_generic_deinit, arginfo_mcrypt_generic_deinit)
  216. PHP_FE(mcrypt_enc_self_test, arginfo_mcrypt_enc_self_test)
  217. PHP_FE(mcrypt_enc_is_block_algorithm_mode, arginfo_mcrypt_enc_is_block_algorithm_mode)
  218. PHP_FE(mcrypt_enc_is_block_algorithm, arginfo_mcrypt_enc_is_block_algorithm)
  219. PHP_FE(mcrypt_enc_is_block_mode, arginfo_mcrypt_enc_is_block_mode)
  220. PHP_FE(mcrypt_enc_get_block_size, arginfo_mcrypt_enc_get_block_size)
  221. PHP_FE(mcrypt_enc_get_key_size, arginfo_mcrypt_enc_get_key_size)
  222. PHP_FE(mcrypt_enc_get_supported_key_sizes, arginfo_mcrypt_enc_get_supported_key_sizes)
  223. PHP_FE(mcrypt_enc_get_iv_size, arginfo_mcrypt_enc_get_iv_size)
  224. PHP_FE(mcrypt_enc_get_algorithms_name, arginfo_mcrypt_enc_get_algorithms_name)
  225. PHP_FE(mcrypt_enc_get_modes_name, arginfo_mcrypt_enc_get_modes_name)
  226. PHP_FE(mcrypt_module_self_test, arginfo_mcrypt_module_self_test)
  227. PHP_FE(mcrypt_module_is_block_algorithm_mode, arginfo_mcrypt_module_is_block_algorithm_mode)
  228. PHP_FE(mcrypt_module_is_block_algorithm, arginfo_mcrypt_module_is_block_algorithm)
  229. PHP_FE(mcrypt_module_is_block_mode, arginfo_mcrypt_module_is_block_mode)
  230. PHP_FE(mcrypt_module_get_algo_block_size, arginfo_mcrypt_module_get_algo_block_size)
  231. PHP_FE(mcrypt_module_get_algo_key_size, arginfo_mcrypt_module_get_algo_key_size)
  232. PHP_FE(mcrypt_module_get_supported_key_sizes, arginfo_mcrypt_module_get_supported_key_sizes)
  233. PHP_FE(mcrypt_module_close, arginfo_mcrypt_module_close)
  234. PHP_FE_END
  235. };
  236. /* }}} */
  237. static PHP_MINFO_FUNCTION(mcrypt);
  238. static PHP_MINIT_FUNCTION(mcrypt);
  239. static PHP_MSHUTDOWN_FUNCTION(mcrypt);
  240. static PHP_GINIT_FUNCTION(mcrypt);
  241. static PHP_GSHUTDOWN_FUNCTION(mcrypt);
  242. ZEND_DECLARE_MODULE_GLOBALS(mcrypt)
  243. zend_module_entry mcrypt_module_entry = {
  244. STANDARD_MODULE_HEADER,
  245. "mcrypt",
  246. mcrypt_functions,
  247. PHP_MINIT(mcrypt), PHP_MSHUTDOWN(mcrypt),
  248. NULL, NULL,
  249. PHP_MINFO(mcrypt),
  250. NO_VERSION_YET,
  251. PHP_MODULE_GLOBALS(mcrypt),
  252. PHP_GINIT(mcrypt),
  253. PHP_GSHUTDOWN(mcrypt),
  254. NULL,
  255. STANDARD_MODULE_PROPERTIES_EX
  256. };
  257. #ifdef COMPILE_DL_MCRYPT
  258. ZEND_GET_MODULE(mcrypt)
  259. #endif
  260. #define MCRYPT_ENCRYPT 0
  261. #define MCRYPT_DECRYPT 1
  262. typedef enum {
  263. RANDOM = 0,
  264. URANDOM,
  265. RAND
  266. } iv_source;
  267. #define MCRYPT_GET_INI \
  268. cipher_dir_string = MCG(algorithms_dir); \
  269. module_dir_string = MCG(modes_dir);
  270. /*
  271. * #warning is not ANSI C
  272. * #warning Invalidate resource if the param count is wrong, or other problems
  273. * #warning occurred during functions.
  274. */
  275. #define MCRYPT_GET_CRYPT_ARGS \
  276. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "sssZ|s", \
  277. &cipher, &cipher_len, &key, &key_len, &data, &data_len, &mode, &iv, &iv_len) == FAILURE) { \
  278. return; \
  279. }
  280. #define MCRYPT_GET_TD_ARG \
  281. zval *mcryptind; \
  282. php_mcrypt *pm; \
  283. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "r", &mcryptind) == FAILURE) { \
  284. return; \
  285. } \
  286. ZEND_FETCH_RESOURCE (pm, php_mcrypt *, &mcryptind, -1, "MCrypt", le_mcrypt);
  287. #define MCRYPT_GET_MODE_DIR_ARGS(DIRECTORY) \
  288. char *dir = NULL; \
  289. int dir_len; \
  290. char *module; \
  291. int module_len; \
  292. if (zend_parse_parameters (ZEND_NUM_ARGS() TSRMLS_CC, \
  293. "s|s", &module, &module_len, &dir, &dir_len) == FAILURE) { \
  294. return; \
  295. }
  296. #define MCRYPT_OPEN_MODULE_FAILED "Module initialization failed"
  297. #define MCRYPT_ENTRY2_2_4(a,b) REGISTER_STRING_CONSTANT("MCRYPT_" #a, b, CONST_PERSISTENT)
  298. #define MCRYPT_ENTRY2_4(a) MCRYPT_ENTRY_NAMED(a, a)
  299. #define PHP_MCRYPT_INIT_CHECK \
  300. if (!pm->init) { \
  301. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Operation disallowed prior to mcrypt_generic_init()."); \
  302. RETURN_FALSE; \
  303. } \
  304. PHP_INI_BEGIN()
  305. STD_PHP_INI_ENTRY("mcrypt.algorithms_dir", NULL, PHP_INI_ALL, OnUpdateString, algorithms_dir, zend_mcrypt_globals, mcrypt_globals)
  306. STD_PHP_INI_ENTRY("mcrypt.modes_dir", NULL, PHP_INI_ALL, OnUpdateString, modes_dir, zend_mcrypt_globals, mcrypt_globals)
  307. PHP_INI_END()
  308. static void php_mcrypt_module_dtor(zend_rsrc_list_entry *rsrc TSRMLS_DC) /* {{{ */
  309. {
  310. php_mcrypt *pm = (php_mcrypt *) rsrc->ptr;
  311. if (pm) {
  312. mcrypt_generic_deinit(pm->td);
  313. mcrypt_module_close(pm->td);
  314. efree(pm);
  315. pm = NULL;
  316. }
  317. }
  318. /* }}} */
  319. static PHP_GINIT_FUNCTION(mcrypt)
  320. {
  321. mcrypt_globals->fd[RANDOM] = -1;
  322. mcrypt_globals->fd[URANDOM] = -1;
  323. }
  324. static PHP_GSHUTDOWN_FUNCTION(mcrypt)
  325. {
  326. if (mcrypt_globals->fd[RANDOM] > 0) {
  327. close(mcrypt_globals->fd[RANDOM]);
  328. mcrypt_globals->fd[RANDOM] = -1;
  329. }
  330. if (mcrypt_globals->fd[URANDOM] > 0) {
  331. close(mcrypt_globals->fd[URANDOM]);
  332. mcrypt_globals->fd[URANDOM] = -1;
  333. }
  334. }
  335. static PHP_MINIT_FUNCTION(mcrypt) /* {{{ */
  336. {
  337. le_mcrypt = zend_register_list_destructors_ex(php_mcrypt_module_dtor, NULL, "mcrypt", module_number);
  338. /* modes for mcrypt_??? routines */
  339. REGISTER_LONG_CONSTANT("MCRYPT_ENCRYPT", 0, CONST_PERSISTENT);
  340. REGISTER_LONG_CONSTANT("MCRYPT_DECRYPT", 1, CONST_PERSISTENT);
  341. /* sources for mcrypt_create_iv */
  342. REGISTER_LONG_CONSTANT("MCRYPT_DEV_RANDOM", RANDOM, CONST_PERSISTENT);
  343. REGISTER_LONG_CONSTANT("MCRYPT_DEV_URANDOM", URANDOM, CONST_PERSISTENT);
  344. REGISTER_LONG_CONSTANT("MCRYPT_RAND", RAND, CONST_PERSISTENT);
  345. /* ciphers */
  346. MCRYPT_ENTRY2_2_4(3DES, "tripledes");
  347. MCRYPT_ENTRY2_2_4(ARCFOUR_IV, "arcfour-iv");
  348. MCRYPT_ENTRY2_2_4(ARCFOUR, "arcfour");
  349. MCRYPT_ENTRY2_2_4(BLOWFISH, "blowfish");
  350. MCRYPT_ENTRY2_2_4(BLOWFISH_COMPAT, "blowfish-compat");
  351. MCRYPT_ENTRY2_2_4(CAST_128, "cast-128");
  352. MCRYPT_ENTRY2_2_4(CAST_256, "cast-256");
  353. MCRYPT_ENTRY2_2_4(CRYPT, "crypt");
  354. MCRYPT_ENTRY2_2_4(DES, "des");
  355. MCRYPT_ENTRY2_2_4(ENIGNA, "crypt");
  356. MCRYPT_ENTRY2_2_4(GOST, "gost");
  357. MCRYPT_ENTRY2_2_4(LOKI97, "loki97");
  358. MCRYPT_ENTRY2_2_4(PANAMA, "panama");
  359. MCRYPT_ENTRY2_2_4(RC2, "rc2");
  360. MCRYPT_ENTRY2_2_4(RIJNDAEL_128, "rijndael-128");
  361. MCRYPT_ENTRY2_2_4(RIJNDAEL_192, "rijndael-192");
  362. MCRYPT_ENTRY2_2_4(RIJNDAEL_256, "rijndael-256");
  363. MCRYPT_ENTRY2_2_4(SAFER64, "safer-sk64");
  364. MCRYPT_ENTRY2_2_4(SAFER128, "safer-sk128");
  365. MCRYPT_ENTRY2_2_4(SAFERPLUS, "saferplus");
  366. MCRYPT_ENTRY2_2_4(SERPENT, "serpent");
  367. MCRYPT_ENTRY2_2_4(THREEWAY, "threeway");
  368. MCRYPT_ENTRY2_2_4(TRIPLEDES, "tripledes");
  369. MCRYPT_ENTRY2_2_4(TWOFISH, "twofish");
  370. MCRYPT_ENTRY2_2_4(WAKE, "wake");
  371. MCRYPT_ENTRY2_2_4(XTEA, "xtea");
  372. MCRYPT_ENTRY2_2_4(IDEA, "idea");
  373. MCRYPT_ENTRY2_2_4(MARS, "mars");
  374. MCRYPT_ENTRY2_2_4(RC6, "rc6");
  375. MCRYPT_ENTRY2_2_4(SKIPJACK, "skipjack");
  376. /* modes */
  377. MCRYPT_ENTRY2_2_4(MODE_CBC, "cbc");
  378. MCRYPT_ENTRY2_2_4(MODE_CFB, "cfb");
  379. MCRYPT_ENTRY2_2_4(MODE_ECB, "ecb");
  380. MCRYPT_ENTRY2_2_4(MODE_NOFB, "nofb");
  381. MCRYPT_ENTRY2_2_4(MODE_OFB, "ofb");
  382. MCRYPT_ENTRY2_2_4(MODE_STREAM, "stream");
  383. REGISTER_INI_ENTRIES();
  384. php_stream_filter_register_factory("mcrypt.*", &php_mcrypt_filter_factory TSRMLS_CC);
  385. php_stream_filter_register_factory("mdecrypt.*", &php_mcrypt_filter_factory TSRMLS_CC);
  386. return SUCCESS;
  387. }
  388. /* }}} */
  389. static PHP_MSHUTDOWN_FUNCTION(mcrypt) /* {{{ */
  390. {
  391. php_stream_filter_unregister_factory("mcrypt.*" TSRMLS_CC);
  392. php_stream_filter_unregister_factory("mdecrypt.*" TSRMLS_CC);
  393. UNREGISTER_INI_ENTRIES();
  394. return SUCCESS;
  395. }
  396. /* }}} */
  397. #include "ext/standard/php_smart_str.h"
  398. PHP_MINFO_FUNCTION(mcrypt) /* {{{ */
  399. {
  400. char **modules;
  401. char mcrypt_api_no[16];
  402. int i, count;
  403. smart_str tmp1 = {0};
  404. smart_str tmp2 = {0};
  405. modules = mcrypt_list_algorithms(MCG(algorithms_dir), &count);
  406. if (count == 0) {
  407. smart_str_appends(&tmp1, "none");
  408. }
  409. for (i = 0; i < count; i++) {
  410. smart_str_appends(&tmp1, modules[i]);
  411. smart_str_appendc(&tmp1, ' ');
  412. }
  413. smart_str_0(&tmp1);
  414. mcrypt_free_p(modules, count);
  415. modules = mcrypt_list_modes(MCG(modes_dir), &count);
  416. if (count == 0) {
  417. smart_str_appends(&tmp2, "none");
  418. }
  419. for (i = 0; i < count; i++) {
  420. smart_str_appends(&tmp2, modules[i]);
  421. smart_str_appendc(&tmp2, ' ');
  422. }
  423. smart_str_0 (&tmp2);
  424. mcrypt_free_p (modules, count);
  425. snprintf (mcrypt_api_no, 16, "%d", MCRYPT_API_VERSION);
  426. php_info_print_table_start();
  427. php_info_print_table_header(2, "mcrypt support", "enabled");
  428. php_info_print_table_header(2, "mcrypt_filter support", "enabled");
  429. php_info_print_table_row(2, "Version", LIBMCRYPT_VERSION);
  430. php_info_print_table_row(2, "Api No", mcrypt_api_no);
  431. php_info_print_table_row(2, "Supported ciphers", tmp1.c);
  432. php_info_print_table_row(2, "Supported modes", tmp2.c);
  433. smart_str_free(&tmp1);
  434. smart_str_free(&tmp2);
  435. php_info_print_table_end();
  436. DISPLAY_INI_ENTRIES();
  437. }
  438. /* }}} */
  439. /* {{{ proto resource mcrypt_module_open(string cipher, string cipher_directory, string mode, string mode_directory)
  440. Opens the module of the algorithm and the mode to be used */
  441. PHP_FUNCTION(mcrypt_module_open)
  442. {
  443. char *cipher, *cipher_dir;
  444. char *mode, *mode_dir;
  445. int cipher_len, cipher_dir_len;
  446. int mode_len, mode_dir_len;
  447. MCRYPT td;
  448. php_mcrypt *pm;
  449. if (zend_parse_parameters (ZEND_NUM_ARGS() TSRMLS_CC, "ssss",
  450. &cipher, &cipher_len, &cipher_dir, &cipher_dir_len,
  451. &mode, &mode_len, &mode_dir, &mode_dir_len)) {
  452. return;
  453. }
  454. td = mcrypt_module_open (
  455. cipher,
  456. cipher_dir_len > 0 ? cipher_dir : MCG(algorithms_dir),
  457. mode,
  458. mode_dir_len > 0 ? mode_dir : MCG(modes_dir)
  459. );
  460. if (td == MCRYPT_FAILED) {
  461. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Could not open encryption module");
  462. RETURN_FALSE;
  463. } else {
  464. pm = emalloc(sizeof(php_mcrypt));
  465. pm->td = td;
  466. pm->init = 0;
  467. ZEND_REGISTER_RESOURCE(return_value, pm, le_mcrypt);
  468. }
  469. }
  470. /* }}} */
  471. /* {{{ proto int mcrypt_generic_init(resource td, string key, string iv)
  472. This function initializes all buffers for the specific module */
  473. PHP_FUNCTION(mcrypt_generic_init)
  474. {
  475. char *key, *iv;
  476. int key_len, iv_len;
  477. zval *mcryptind;
  478. unsigned char *key_s, *iv_s;
  479. int max_key_size, key_size, iv_size;
  480. php_mcrypt *pm;
  481. int result = 0;
  482. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "rss", &mcryptind, &key, &key_len, &iv, &iv_len) == FAILURE) {
  483. return;
  484. }
  485. ZEND_FETCH_RESOURCE(pm, php_mcrypt *, &mcryptind, -1, "MCrypt", le_mcrypt);
  486. max_key_size = mcrypt_enc_get_key_size(pm->td);
  487. iv_size = mcrypt_enc_get_iv_size(pm->td);
  488. if (key_len == 0) {
  489. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Key size is 0");
  490. }
  491. key_s = emalloc(key_len);
  492. memset(key_s, 0, key_len);
  493. iv_s = emalloc(iv_size + 1);
  494. memset(iv_s, 0, iv_size + 1);
  495. if (key_len > max_key_size) {
  496. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Key size too large; supplied length: %d, max: %d", key_len, max_key_size);
  497. key_size = max_key_size;
  498. } else {
  499. key_size = key_len;
  500. }
  501. memcpy(key_s, key, key_len);
  502. if (iv_len != iv_size) {
  503. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Iv size incorrect; supplied length: %d, needed: %d", iv_len, iv_size);
  504. if (iv_len > iv_size) {
  505. iv_len = iv_size;
  506. }
  507. }
  508. memcpy(iv_s, iv, iv_len);
  509. mcrypt_generic_deinit(pm->td);
  510. result = mcrypt_generic_init(pm->td, key_s, key_size, iv_s);
  511. /* If this function fails, close the mcrypt module to prevent crashes
  512. * when further functions want to access this resource */
  513. if (result < 0) {
  514. zend_list_delete(Z_LVAL_P(mcryptind));
  515. switch (result) {
  516. case -3:
  517. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Key length incorrect");
  518. break;
  519. case -4:
  520. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Memory allocation error");
  521. break;
  522. case -1:
  523. default:
  524. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unknown error");
  525. break;
  526. }
  527. } else {
  528. pm->init = 1;
  529. }
  530. RETVAL_LONG(result);
  531. efree(iv_s);
  532. efree(key_s);
  533. }
  534. /* }}} */
  535. /* {{{ proto string mcrypt_generic(resource td, string data)
  536. This function encrypts the plaintext */
  537. PHP_FUNCTION(mcrypt_generic)
  538. {
  539. zval *mcryptind;
  540. char *data;
  541. int data_len;
  542. php_mcrypt *pm;
  543. char* data_s;
  544. int block_size, data_size;
  545. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "rs", &mcryptind, &data, &data_len) == FAILURE) {
  546. return;
  547. }
  548. ZEND_FETCH_RESOURCE(pm, php_mcrypt *, &mcryptind, -1, "MCrypt", le_mcrypt);
  549. PHP_MCRYPT_INIT_CHECK
  550. if (data_len == 0) {
  551. php_error_docref(NULL TSRMLS_CC, E_WARNING, "An empty string was passed");
  552. RETURN_FALSE
  553. }
  554. /* Check blocksize */
  555. if (mcrypt_enc_is_block_mode(pm->td) == 1) { /* It's a block algorithm */
  556. block_size = mcrypt_enc_get_block_size(pm->td);
  557. data_size = (((data_len - 1) / block_size) + 1) * block_size;
  558. if (data_size <= 0) {
  559. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Integer overflow in data size");
  560. RETURN_FALSE;
  561. }
  562. data_s = emalloc(data_size + 1);
  563. memset(data_s, 0, data_size);
  564. memcpy(data_s, data, data_len);
  565. } else { /* It's not a block algorithm */
  566. data_size = data_len;
  567. data_s = emalloc(data_size + 1);
  568. memset(data_s, 0, data_size);
  569. memcpy(data_s, data, data_len);
  570. }
  571. mcrypt_generic(pm->td, data_s, data_size);
  572. data_s[data_size] = '\0';
  573. RETVAL_STRINGL(data_s, data_size, 1);
  574. efree(data_s);
  575. }
  576. /* }}} */
  577. /* {{{ proto string mdecrypt_generic(resource td, string data)
  578. This function decrypts the plaintext */
  579. PHP_FUNCTION(mdecrypt_generic)
  580. {
  581. zval *mcryptind;
  582. char *data;
  583. int data_len;
  584. php_mcrypt *pm;
  585. char* data_s;
  586. int block_size, data_size;
  587. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "rs", &mcryptind, &data, &data_len) == FAILURE) {
  588. return;
  589. }
  590. ZEND_FETCH_RESOURCE(pm, php_mcrypt * , &mcryptind, -1, "MCrypt", le_mcrypt);
  591. PHP_MCRYPT_INIT_CHECK
  592. if (data_len == 0) {
  593. php_error_docref(NULL TSRMLS_CC, E_WARNING, "An empty string was passed");
  594. RETURN_FALSE
  595. }
  596. /* Check blocksize */
  597. if (mcrypt_enc_is_block_mode(pm->td) == 1) { /* It's a block algorithm */
  598. block_size = mcrypt_enc_get_block_size(pm->td);
  599. data_size = (((data_len - 1) / block_size) + 1) * block_size;
  600. if (data_size <= 0) {
  601. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Integer overflow in data size");
  602. RETURN_FALSE;
  603. }
  604. data_s = emalloc(data_size + 1);
  605. memset(data_s, 0, data_size);
  606. memcpy(data_s, data, data_len);
  607. } else { /* It's not a block algorithm */
  608. data_size = data_len;
  609. data_s = emalloc(data_size + 1);
  610. memset(data_s, 0, data_size);
  611. memcpy(data_s, data, data_len);
  612. }
  613. mdecrypt_generic(pm->td, data_s, data_size);
  614. RETVAL_STRINGL(data_s, data_size, 1);
  615. efree(data_s);
  616. }
  617. /* }}} */
  618. /* {{{ proto array mcrypt_enc_get_supported_key_sizes(resource td)
  619. This function decrypts the crypttext */
  620. PHP_FUNCTION(mcrypt_enc_get_supported_key_sizes)
  621. {
  622. int i, count = 0;
  623. int *key_sizes;
  624. MCRYPT_GET_TD_ARG
  625. array_init(return_value);
  626. key_sizes = mcrypt_enc_get_supported_key_sizes(pm->td, &count);
  627. for (i = 0; i < count; i++) {
  628. add_index_long(return_value, i, key_sizes[i]);
  629. }
  630. mcrypt_free(key_sizes);
  631. }
  632. /* }}} */
  633. /* {{{ proto int mcrypt_enc_self_test(resource td)
  634. This function runs the self test on the algorithm specified by the descriptor td */
  635. PHP_FUNCTION(mcrypt_enc_self_test)
  636. {
  637. MCRYPT_GET_TD_ARG
  638. RETURN_LONG(mcrypt_enc_self_test(pm->td));
  639. }
  640. /* }}} */
  641. /* {{{ proto bool mcrypt_module_close(resource td)
  642. Free the descriptor td */
  643. PHP_FUNCTION(mcrypt_module_close)
  644. {
  645. MCRYPT_GET_TD_ARG
  646. zend_list_delete(Z_LVAL_P(mcryptind));
  647. RETURN_TRUE;
  648. }
  649. /* }}} */
  650. /* {{{ proto bool mcrypt_generic_deinit(resource td)
  651. This function terminates encrypt specified by the descriptor td */
  652. PHP_FUNCTION(mcrypt_generic_deinit)
  653. {
  654. MCRYPT_GET_TD_ARG
  655. if (mcrypt_generic_deinit(pm->td) < 0) {
  656. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Could not terminate encryption specifier");
  657. RETURN_FALSE
  658. }
  659. pm->init = 0;
  660. RETURN_TRUE
  661. }
  662. /* }}} */
  663. /* {{{ proto bool mcrypt_enc_is_block_algorithm_mode(resource td)
  664. Returns TRUE if the mode is for use with block algorithms */
  665. PHP_FUNCTION(mcrypt_enc_is_block_algorithm_mode)
  666. {
  667. MCRYPT_GET_TD_ARG
  668. if (mcrypt_enc_is_block_algorithm_mode(pm->td) == 1) {
  669. RETURN_TRUE
  670. } else {
  671. RETURN_FALSE
  672. }
  673. }
  674. /* }}} */
  675. /* {{{ proto bool mcrypt_enc_is_block_algorithm(resource td)
  676. Returns TRUE if the alrogithm is a block algorithms */
  677. PHP_FUNCTION(mcrypt_enc_is_block_algorithm)
  678. {
  679. MCRYPT_GET_TD_ARG
  680. if (mcrypt_enc_is_block_algorithm(pm->td) == 1) {
  681. RETURN_TRUE
  682. } else {
  683. RETURN_FALSE
  684. }
  685. }
  686. /* }}} */
  687. /* {{{ proto bool mcrypt_enc_is_block_mode(resource td)
  688. Returns TRUE if the mode outputs blocks */
  689. PHP_FUNCTION(mcrypt_enc_is_block_mode)
  690. {
  691. MCRYPT_GET_TD_ARG
  692. if (mcrypt_enc_is_block_mode(pm->td) == 1) {
  693. RETURN_TRUE
  694. } else {
  695. RETURN_FALSE
  696. }
  697. }
  698. /* }}} */
  699. /* {{{ proto int mcrypt_enc_get_block_size(resource td)
  700. Returns the block size of the cipher specified by the descriptor td */
  701. PHP_FUNCTION(mcrypt_enc_get_block_size)
  702. {
  703. MCRYPT_GET_TD_ARG
  704. RETURN_LONG(mcrypt_enc_get_block_size(pm->td));
  705. }
  706. /* }}} */
  707. /* {{{ proto int mcrypt_enc_get_key_size(resource td)
  708. Returns the maximum supported key size in bytes of the algorithm specified by the descriptor td */
  709. PHP_FUNCTION(mcrypt_enc_get_key_size)
  710. {
  711. MCRYPT_GET_TD_ARG
  712. RETURN_LONG(mcrypt_enc_get_key_size(pm->td));
  713. }
  714. /* }}} */
  715. /* {{{ proto int mcrypt_enc_get_iv_size(resource td)
  716. Returns the size of the IV in bytes of the algorithm specified by the descriptor td */
  717. PHP_FUNCTION(mcrypt_enc_get_iv_size)
  718. {
  719. MCRYPT_GET_TD_ARG
  720. RETURN_LONG(mcrypt_enc_get_iv_size(pm->td));
  721. }
  722. /* }}} */
  723. /* {{{ proto string mcrypt_enc_get_algorithms_name(resource td)
  724. Returns the name of the algorithm specified by the descriptor td */
  725. PHP_FUNCTION(mcrypt_enc_get_algorithms_name)
  726. {
  727. char *name;
  728. MCRYPT_GET_TD_ARG
  729. name = mcrypt_enc_get_algorithms_name(pm->td);
  730. RETVAL_STRING(name, 1);
  731. mcrypt_free(name);
  732. }
  733. /* }}} */
  734. /* {{{ proto string mcrypt_enc_get_modes_name(resource td)
  735. Returns the name of the mode specified by the descriptor td */
  736. PHP_FUNCTION(mcrypt_enc_get_modes_name)
  737. {
  738. char *name;
  739. MCRYPT_GET_TD_ARG
  740. name = mcrypt_enc_get_modes_name(pm->td);
  741. RETVAL_STRING(name, 1);
  742. mcrypt_free(name);
  743. }
  744. /* }}} */
  745. /* {{{ proto bool mcrypt_module_self_test(string algorithm [, string lib_dir])
  746. Does a self test of the module "module" */
  747. PHP_FUNCTION(mcrypt_module_self_test)
  748. {
  749. MCRYPT_GET_MODE_DIR_ARGS(algorithms_dir);
  750. if (mcrypt_module_self_test(module, dir) == 0) {
  751. RETURN_TRUE;
  752. } else {
  753. RETURN_FALSE;
  754. }
  755. }
  756. /* }}} */
  757. /* {{{ proto bool mcrypt_module_is_block_algorithm_mode(string mode [, string lib_dir])
  758. Returns TRUE if the mode is for use with block algorithms */
  759. PHP_FUNCTION(mcrypt_module_is_block_algorithm_mode)
  760. {
  761. MCRYPT_GET_MODE_DIR_ARGS(modes_dir)
  762. if (mcrypt_module_is_block_algorithm_mode(module, dir) == 1) {
  763. RETURN_TRUE;
  764. } else {
  765. RETURN_FALSE;
  766. }
  767. }
  768. /* }}} */
  769. /* {{{ proto bool mcrypt_module_is_block_algorithm(string algorithm [, string lib_dir])
  770. Returns TRUE if the algorithm is a block algorithm */
  771. PHP_FUNCTION(mcrypt_module_is_block_algorithm)
  772. {
  773. MCRYPT_GET_MODE_DIR_ARGS(algorithms_dir)
  774. if (mcrypt_module_is_block_algorithm(module, dir) == 1) {
  775. RETURN_TRUE;
  776. } else {
  777. RETURN_FALSE;
  778. }
  779. }
  780. /* }}} */
  781. /* {{{ proto bool mcrypt_module_is_block_mode(string mode [, string lib_dir])
  782. Returns TRUE if the mode outputs blocks of bytes */
  783. PHP_FUNCTION(mcrypt_module_is_block_mode)
  784. {
  785. MCRYPT_GET_MODE_DIR_ARGS(modes_dir)
  786. if (mcrypt_module_is_block_mode(module, dir) == 1) {
  787. RETURN_TRUE;
  788. } else {
  789. RETURN_FALSE;
  790. }
  791. }
  792. /* }}} */
  793. /* {{{ proto int mcrypt_module_get_algo_block_size(string algorithm [, string lib_dir])
  794. Returns the block size of the algorithm */
  795. PHP_FUNCTION(mcrypt_module_get_algo_block_size)
  796. {
  797. MCRYPT_GET_MODE_DIR_ARGS(algorithms_dir)
  798. RETURN_LONG(mcrypt_module_get_algo_block_size(module, dir));
  799. }
  800. /* }}} */
  801. /* {{{ proto int mcrypt_module_get_algo_key_size(string algorithm [, string lib_dir])
  802. Returns the maximum supported key size of the algorithm */
  803. PHP_FUNCTION(mcrypt_module_get_algo_key_size)
  804. {
  805. MCRYPT_GET_MODE_DIR_ARGS(algorithms_dir);
  806. RETURN_LONG(mcrypt_module_get_algo_key_size(module, dir));
  807. }
  808. /* }}} */
  809. /* {{{ proto array mcrypt_module_get_supported_key_sizes(string algorithm [, string lib_dir])
  810. This function decrypts the crypttext */
  811. PHP_FUNCTION(mcrypt_module_get_supported_key_sizes)
  812. {
  813. int i, count = 0;
  814. int *key_sizes;
  815. MCRYPT_GET_MODE_DIR_ARGS(algorithms_dir)
  816. array_init(return_value);
  817. key_sizes = mcrypt_module_get_algo_supported_key_sizes(module, dir, &count);
  818. for (i = 0; i < count; i++) {
  819. add_index_long(return_value, i, key_sizes[i]);
  820. }
  821. mcrypt_free(key_sizes);
  822. }
  823. /* }}} */
  824. /* {{{ proto array mcrypt_list_algorithms([string lib_dir])
  825. List all algorithms in "module_dir" */
  826. PHP_FUNCTION(mcrypt_list_algorithms)
  827. {
  828. char **modules;
  829. char *lib_dir = MCG(algorithms_dir);
  830. int lib_dir_len;
  831. int i, count;
  832. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "|s",
  833. &lib_dir, &lib_dir_len) == FAILURE) {
  834. return;
  835. }
  836. array_init(return_value);
  837. modules = mcrypt_list_algorithms(lib_dir, &count);
  838. if (count == 0) {
  839. php_error_docref(NULL TSRMLS_CC, E_WARNING, "No algorithms found in module dir");
  840. }
  841. for (i = 0; i < count; i++) {
  842. add_index_string(return_value, i, modules[i], 1);
  843. }
  844. mcrypt_free_p(modules, count);
  845. }
  846. /* }}} */
  847. /* {{{ proto array mcrypt_list_modes([string lib_dir])
  848. List all modes "module_dir" */
  849. PHP_FUNCTION(mcrypt_list_modes)
  850. {
  851. char **modules;
  852. char *lib_dir = MCG(modes_dir);
  853. int lib_dir_len;
  854. int i, count;
  855. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "|s",
  856. &lib_dir, &lib_dir_len) == FAILURE) {
  857. return;
  858. }
  859. array_init(return_value);
  860. modules = mcrypt_list_modes(lib_dir, &count);
  861. if (count == 0) {
  862. php_error_docref(NULL TSRMLS_CC, E_WARNING, "No modes found in module dir");
  863. }
  864. for (i = 0; i < count; i++) {
  865. add_index_string(return_value, i, modules[i], 1);
  866. }
  867. mcrypt_free_p(modules, count);
  868. }
  869. /* }}} */
  870. /* {{{ proto int mcrypt_get_key_size(string cipher, string module)
  871. Get the key size of cipher */
  872. PHP_FUNCTION(mcrypt_get_key_size)
  873. {
  874. char *cipher;
  875. char *module;
  876. int cipher_len, module_len;
  877. char *cipher_dir_string;
  878. char *module_dir_string;
  879. MCRYPT td;
  880. MCRYPT_GET_INI
  881. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "ss",
  882. &cipher, &cipher_len, &module, &module_len) == FAILURE) {
  883. return;
  884. }
  885. td = mcrypt_module_open(cipher, cipher_dir_string, module, module_dir_string);
  886. if (td != MCRYPT_FAILED) {
  887. RETVAL_LONG(mcrypt_enc_get_key_size(td));
  888. mcrypt_module_close(td);
  889. } else {
  890. php_error_docref(NULL TSRMLS_CC, E_WARNING, MCRYPT_OPEN_MODULE_FAILED);
  891. RETURN_FALSE;
  892. }
  893. }
  894. /* }}} */
  895. /* {{{ proto int mcrypt_get_block_size(string cipher, string module)
  896. Get the key size of cipher */
  897. PHP_FUNCTION(mcrypt_get_block_size)
  898. {
  899. char *cipher;
  900. char *module;
  901. int cipher_len, module_len;
  902. char *cipher_dir_string;
  903. char *module_dir_string;
  904. MCRYPT td;
  905. MCRYPT_GET_INI
  906. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "ss",
  907. &cipher, &cipher_len, &module, &module_len) == FAILURE) {
  908. return;
  909. }
  910. td = mcrypt_module_open(cipher, cipher_dir_string, module, module_dir_string);
  911. if (td != MCRYPT_FAILED) {
  912. RETVAL_LONG(mcrypt_enc_get_block_size(td));
  913. mcrypt_module_close(td);
  914. } else {
  915. php_error_docref(NULL TSRMLS_CC, E_WARNING, MCRYPT_OPEN_MODULE_FAILED);
  916. RETURN_FALSE;
  917. }
  918. }
  919. /* }}} */
  920. /* {{{ proto int mcrypt_get_iv_size(string cipher, string module)
  921. Get the IV size of cipher (Usually the same as the blocksize) */
  922. PHP_FUNCTION(mcrypt_get_iv_size)
  923. {
  924. char *cipher;
  925. char *module;
  926. int cipher_len, module_len;
  927. char *cipher_dir_string;
  928. char *module_dir_string;
  929. MCRYPT td;
  930. MCRYPT_GET_INI
  931. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "ss",
  932. &cipher, &cipher_len, &module, &module_len) == FAILURE) {
  933. return;
  934. }
  935. td = mcrypt_module_open(cipher, cipher_dir_string, module, module_dir_string);
  936. if (td != MCRYPT_FAILED) {
  937. RETVAL_LONG(mcrypt_enc_get_iv_size(td));
  938. mcrypt_module_close(td);
  939. } else {
  940. php_error_docref(NULL TSRMLS_CC, E_WARNING, MCRYPT_OPEN_MODULE_FAILED);
  941. RETURN_FALSE;
  942. }
  943. }
  944. /* }}} */
  945. /* {{{ proto string mcrypt_get_cipher_name(string cipher)
  946. Get the key size of cipher */
  947. PHP_FUNCTION(mcrypt_get_cipher_name)
  948. {
  949. char *cipher_dir_string;
  950. char *module_dir_string;
  951. char *cipher_name;
  952. char *cipher;
  953. int cipher_len;
  954. MCRYPT td;
  955. MCRYPT_GET_INI
  956. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "s",
  957. &cipher, &cipher_len) == FAILURE) {
  958. return;
  959. }
  960. /* The code below is actually not very nice, but I didn't see a better
  961. * method */
  962. td = mcrypt_module_open(cipher, cipher_dir_string, "ecb", module_dir_string);
  963. if (td != MCRYPT_FAILED) {
  964. cipher_name = mcrypt_enc_get_algorithms_name(td);
  965. mcrypt_module_close(td);
  966. RETVAL_STRING(cipher_name,1);
  967. mcrypt_free(cipher_name);
  968. } else {
  969. td = mcrypt_module_open(cipher, cipher_dir_string, "stream", module_dir_string);
  970. if (td != MCRYPT_FAILED) {
  971. cipher_name = mcrypt_enc_get_algorithms_name(td);
  972. mcrypt_module_close(td);
  973. RETVAL_STRING(cipher_name,1);
  974. mcrypt_free(cipher_name);
  975. } else {
  976. php_error_docref(NULL TSRMLS_CC, E_WARNING, MCRYPT_OPEN_MODULE_FAILED);
  977. RETURN_FALSE;
  978. }
  979. }
  980. }
  981. /* }}} */
  982. static char *php_mcrypt_get_key_size_str(
  983. int max_key_size, const int *key_sizes, int key_size_count) /* {{{ */
  984. {
  985. if (key_size_count == 0) {
  986. char *str;
  987. spprintf(&str, 0, "Only keys of size 1 to %d supported", max_key_size);
  988. return str;
  989. } else if (key_size_count == 1) {
  990. char *str;
  991. spprintf(&str, 0, "Only keys of size %d supported", key_sizes[0]);
  992. return str;
  993. } else {
  994. int i;
  995. smart_str str = {0};
  996. smart_str_appends(&str, "Only keys of sizes ");
  997. for (i = 0; i < key_size_count; ++i) {
  998. if (i == key_size_count - 1) {
  999. smart_str_appends(&str, " or ");
  1000. } else if (i != 0) {
  1001. smart_str_appends(&str, ", ");
  1002. }
  1003. smart_str_append_long(&str, key_sizes[i]);
  1004. }
  1005. smart_str_appends(&str, " supported");
  1006. smart_str_0(&str);
  1007. return str.c;
  1008. }
  1009. }
  1010. /* }}} */
  1011. static zend_bool php_mcrypt_is_valid_key_size(
  1012. int key_size, int max_key_size, int *key_sizes, int key_size_count) /* {{{ */
  1013. {
  1014. int i;
  1015. if (key_size <= 0 || key_size > max_key_size) {
  1016. return 0;
  1017. }
  1018. if (key_size_count == 0) {
  1019. /* All key sizes are valid */
  1020. return 1;
  1021. }
  1022. for (i = 0; i < key_size_count; i++) {
  1023. if (key_sizes[i] == key_size) {
  1024. return 1;
  1025. }
  1026. }
  1027. return 0;
  1028. }
  1029. /* }}} */
  1030. static int php_mcrypt_ensure_valid_key_size(MCRYPT td, int key_size TSRMLS_DC) /* {{{ */
  1031. {
  1032. int key_size_count;
  1033. int max_key_size = mcrypt_enc_get_key_size(td);
  1034. int *key_sizes = mcrypt_enc_get_supported_key_sizes(td, &key_size_count);
  1035. zend_bool is_valid_key_size = php_mcrypt_is_valid_key_size(
  1036. key_size, max_key_size, key_sizes, key_size_count
  1037. );
  1038. if (!is_valid_key_size) {
  1039. char *key_size_str = php_mcrypt_get_key_size_str(
  1040. max_key_size, key_sizes, key_size_count
  1041. );
  1042. php_error_docref(NULL TSRMLS_CC, E_WARNING,
  1043. "Key of size %d not supported by this algorithm. %s", key_size, key_size_str
  1044. );
  1045. efree(key_size_str);
  1046. }
  1047. if (key_sizes) {
  1048. mcrypt_free(key_sizes);
  1049. }
  1050. return is_valid_key_size ? SUCCESS : FAILURE;
  1051. }
  1052. /* }}} */
  1053. static int php_mcrypt_ensure_valid_iv(MCRYPT td, const char *iv, int iv_size TSRMLS_DC) /* {{{ */
  1054. {
  1055. if (mcrypt_enc_mode_has_iv(td) == 1) {
  1056. int expected_iv_size = mcrypt_enc_get_iv_size(td);
  1057. if (expected_iv_size == 0) {
  1058. /* Algorithm does not use IV, even though mode supports it */
  1059. return SUCCESS;
  1060. }
  1061. if (!iv) {
  1062. php_error_docref(NULL TSRMLS_CC, E_WARNING,
  1063. "Encryption mode requires an initialization vector of size %d", expected_iv_size
  1064. );
  1065. return FAILURE;
  1066. }
  1067. if (iv_size != expected_iv_size) {
  1068. php_error_docref(NULL TSRMLS_CC, E_WARNING,
  1069. "Received initialization vector of size %d, but size %d is required "
  1070. "for this encryption mode", iv_size, expected_iv_size
  1071. );
  1072. return FAILURE;
  1073. }
  1074. }
  1075. return SUCCESS;
  1076. }
  1077. /* }}} */
  1078. static void php_mcrypt_do_crypt(char* cipher, const char *key, int key_len, const char *data, int data_len, char *mode, const char *iv, int iv_len, int dencrypt, zval* return_value TSRMLS_DC) /* {{{ */
  1079. {
  1080. char *cipher_dir_string;
  1081. char *module_dir_string;
  1082. unsigned long int data_size;
  1083. char *data_s;
  1084. MCRYPT td;
  1085. MCRYPT_GET_INI
  1086. td = mcrypt_module_open(cipher, cipher_dir_string, mode, module_dir_string);
  1087. if (td == MCRYPT_FAILED) {
  1088. php_error_docref(NULL TSRMLS_CC, E_WARNING, MCRYPT_OPEN_MODULE_FAILED);
  1089. RETURN_FALSE;
  1090. }
  1091. if (php_mcrypt_ensure_valid_key_size(td, key_len TSRMLS_CC) == FAILURE) {
  1092. mcrypt_module_close(td);
  1093. RETURN_FALSE;
  1094. }
  1095. if (php_mcrypt_ensure_valid_iv(td, iv, iv_len TSRMLS_CC) == FAILURE) {
  1096. mcrypt_module_close(td);
  1097. RETURN_FALSE;
  1098. }
  1099. /* Check blocksize */
  1100. if (mcrypt_enc_is_block_mode(td) == 1) { /* It's a block algorithm */
  1101. int block_size = mcrypt_enc_get_block_size(td);
  1102. data_size = (((data_len - 1) / block_size) + 1) * block_size;
  1103. data_s = emalloc(data_size + 1);
  1104. memset(data_s, 0, data_size);
  1105. memcpy(data_s, data, data_len);
  1106. } else { /* It's not a block algorithm */
  1107. data_size = data_len;
  1108. data_s = emalloc(data_size + 1);
  1109. memcpy(data_s, data, data_len);
  1110. }
  1111. if (mcrypt_generic_init(td, (void *) key, key_len, (void *) iv) < 0) {
  1112. efree(data_s);
  1113. php_error_docref(NULL TSRMLS_CC, E_RECOVERABLE_ERROR, "Mcrypt initialisation failed");
  1114. mcrypt_module_close(td);
  1115. RETURN_FALSE;
  1116. }
  1117. if (dencrypt == MCRYPT_ENCRYPT) {
  1118. mcrypt_generic(td, data_s, data_size);
  1119. } else {
  1120. mdecrypt_generic(td, data_s, data_size);
  1121. }
  1122. data_s[data_size] = 0;
  1123. RETVAL_STRINGL(data_s, data_size, 0);
  1124. /* freeing vars */
  1125. mcrypt_generic_end(td);
  1126. }
  1127. /* }}} */
  1128. /* {{{ proto string mcrypt_encrypt(string cipher, string key, string data, string mode, string iv)
  1129. OFB crypt/decrypt data using key key with cipher cipher starting with iv */
  1130. PHP_FUNCTION(mcrypt_encrypt)
  1131. {
  1132. char *cipher, *key, *data, *mode, *iv = NULL;
  1133. int cipher_len, key_len, data_len, mode_len, iv_len = 0;
  1134. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "ssss|s", &cipher, &cipher_len,
  1135. &key, &key_len, &data, &data_len, &mode, &mode_len, &iv, &iv_len) == FAILURE) {
  1136. return;
  1137. }
  1138. php_mcrypt_do_crypt(cipher, key, key_len, data, data_len, mode, iv, iv_len, MCRYPT_ENCRYPT, return_value TSRMLS_CC);
  1139. }
  1140. /* }}} */
  1141. /* {{{ proto string mcrypt_decrypt(string cipher, string key, string data, string mode, string iv)
  1142. OFB crypt/decrypt data using key key with cipher cipher starting with iv */
  1143. PHP_FUNCTION(mcrypt_decrypt)
  1144. {
  1145. char *cipher, *key, *data, *mode, *iv = NULL;
  1146. int cipher_len, key_len, data_len, mode_len, iv_len = 0;
  1147. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "ssss|s", &cipher, &cipher_len,
  1148. &key, &key_len, &data, &data_len, &mode, &mode_len, &iv, &iv_len) == FAILURE) {
  1149. return;
  1150. }
  1151. php_mcrypt_do_crypt(cipher, key, key_len, data, data_len, mode, iv, iv_len, MCRYPT_DECRYPT, return_value TSRMLS_CC);
  1152. }
  1153. /* }}} */
  1154. /* {{{ proto string mcrypt_ecb(int cipher, string key, string data, int mode, string iv)
  1155. ECB crypt/decrypt data using key key with cipher cipher starting with iv */
  1156. PHP_FUNCTION(mcrypt_ecb)
  1157. {
  1158. zval **mode;
  1159. char *cipher, *key, *data, *iv = NULL;
  1160. int cipher_len, key_len, data_len, iv_len = 0;
  1161. MCRYPT_GET_CRYPT_ARGS
  1162. convert_to_long_ex(mode);
  1163. php_mcrypt_do_crypt(cipher, key, key_len, data, data_len, "ecb", iv, iv_len, Z_LVAL_PP(mode), return_value TSRMLS_CC);
  1164. }
  1165. /* }}} */
  1166. /* {{{ proto string mcrypt_cbc(int cipher, string key, string data, int mode, string iv)
  1167. CBC crypt/decrypt data using key key with cipher cipher starting with iv */
  1168. PHP_FUNCTION(mcrypt_cbc)
  1169. {
  1170. zval **mode;
  1171. char *cipher, *key, *data, *iv = NULL;
  1172. int cipher_len, key_len, data_len, iv_len = 0;
  1173. MCRYPT_GET_CRYPT_ARGS
  1174. convert_to_long_ex(mode);
  1175. php_mcrypt_do_crypt(cipher, key, key_len, data, data_len, "cbc", iv, iv_len, Z_LVAL_PP(mode), return_value TSRMLS_CC);
  1176. }
  1177. /* }}} */
  1178. /* {{{ proto string mcrypt_cfb(int cipher, string key, string data, int mode, string iv)
  1179. CFB crypt/decrypt data using key key with cipher cipher starting with iv */
  1180. PHP_FUNCTION(mcrypt_cfb)
  1181. {
  1182. zval **mode;
  1183. char *cipher, *key, *data, *iv = NULL;
  1184. int cipher_len, key_len, data_len, iv_len = 0;
  1185. MCRYPT_GET_CRYPT_ARGS
  1186. convert_to_long_ex(mode);
  1187. php_mcrypt_do_crypt(cipher, key, key_len, data, data_len, "cfb", iv, iv_len, Z_LVAL_PP(mode), return_value TSRMLS_CC);
  1188. }
  1189. /* }}} */
  1190. /* {{{ proto string mcrypt_ofb(int cipher, string key, string data, int mode, string iv)
  1191. OFB crypt/decrypt data using key key with cipher cipher starting with iv */
  1192. PHP_FUNCTION(mcrypt_ofb)
  1193. {
  1194. zval **mode;
  1195. char *cipher, *key, *data, *iv = NULL;
  1196. int cipher_len, key_len, data_len, iv_len = 0;
  1197. MCRYPT_GET_CRYPT_ARGS
  1198. convert_to_long_ex(mode);
  1199. php_mcrypt_do_crypt(cipher, key, key_len, data, data_len, "ofb", iv, iv_len, Z_LVAL_PP(mode), return_value TSRMLS_CC);
  1200. }
  1201. /* }}} */
  1202. /* {{{ proto string mcrypt_create_iv(int size, int source)
  1203. Create an initialization vector (IV) */
  1204. PHP_FUNCTION(mcrypt_create_iv)
  1205. {
  1206. char *iv;
  1207. long source = URANDOM;
  1208. long size;
  1209. int n = 0;
  1210. if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "l|l", &size, &source) == FAILURE) {
  1211. return;
  1212. }
  1213. if (size <= 0 || size >= INT_MAX) {
  1214. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Cannot create an IV with a size of less than 1 or greater than %d", INT_MAX);
  1215. RETURN_FALSE;
  1216. }
  1217. iv = ecalloc(size + 1, 1);
  1218. if (source == RANDOM || source == URANDOM) {
  1219. #if PHP_WIN32
  1220. /* random/urandom equivalent on Windows */
  1221. BYTE *iv_b = (BYTE *) iv;
  1222. if (php_win32_get_random_bytes(iv_b, (size_t) size) == FAILURE){
  1223. efree(iv);
  1224. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Could not gather sufficient random data");
  1225. RETURN_FALSE;
  1226. }
  1227. n = size;
  1228. #else
  1229. int *fd = &MCG(fd[source]);
  1230. size_t read_bytes = 0;
  1231. if (*fd < 0) {
  1232. *fd = open(source == RANDOM ? "/dev/random" : "/dev/urandom", O_RDONLY);
  1233. if (*fd < 0) {
  1234. efree(iv);
  1235. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Cannot open source device");
  1236. RETURN_FALSE;
  1237. }
  1238. }
  1239. while (read_bytes < size) {
  1240. n = read(*fd, iv + read_bytes, size - read_bytes);
  1241. if (n < 0) {
  1242. break;
  1243. }
  1244. read_bytes += n;
  1245. }
  1246. n = read_bytes;
  1247. if (n < size) {
  1248. efree(iv);
  1249. php_error_docref(NULL TSRMLS_CC, E_WARNING, "Could not gather sufficient random data");
  1250. RETURN_FALSE;
  1251. }
  1252. #endif
  1253. } else {
  1254. n = size;
  1255. while (size) {
  1256. iv[--size] = (char) (255.0 * php_rand(TSRMLS_C) / RAND_MAX);
  1257. }
  1258. }
  1259. RETURN_STRINGL(iv, n, 0);
  1260. }
  1261. /* }}} */
  1262. #endif
  1263. /*
  1264. * Local variables:
  1265. * tab-width: 4
  1266. * c-basic-offset: 4
  1267. * End:
  1268. * vim600: sw=4 ts=4 fdm=marker
  1269. * vim<600: sw=4 ts=4
  1270. */