bug68920.phpt 3.4 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495
  1. --TEST--
  2. Bug #68920: peer_fingerprint input checks should be strict
  3. --EXTENSIONS--
  4. openssl
  5. --SKIPIF--
  6. <?php
  7. if (!function_exists("proc_open")) die("skip no proc_open");
  8. ?>
  9. --FILE--
  10. <?php
  11. $certFile = __DIR__ . DIRECTORY_SEPARATOR . 'bug68920.pem.tmp';
  12. $serverCode = <<<'CODE'
  13. $serverUri = "ssl://127.0.0.1:64321";
  14. $serverFlags = STREAM_SERVER_BIND | STREAM_SERVER_LISTEN;
  15. $serverCtx = stream_context_create(['ssl' => [
  16. 'local_cert' => '%s',
  17. ]]);
  18. $server = stream_socket_server($serverUri, $errno, $errstr, $serverFlags, $serverCtx);
  19. phpt_notify();
  20. stream_socket_accept($server, 30);
  21. stream_socket_accept($server, 30);
  22. stream_socket_accept($server, 30);
  23. stream_socket_accept($server, 30);
  24. CODE;
  25. $serverCode = sprintf($serverCode, $certFile);
  26. $clientCode = <<<'CODE'
  27. $serverUri = "ssl://127.0.0.1:64321";
  28. $clientFlags = STREAM_CLIENT_CONNECT;
  29. phpt_wait();
  30. $ctx = stream_context_create(['ssl' => ['verify_peer'=> false, 'peer_fingerprint' => true]]);
  31. $sock = stream_socket_client($serverUri, $errno, $errstr, 30, $clientFlags, $ctx);
  32. var_dump($sock);
  33. $ctx = stream_context_create(['ssl' => ['verify_peer'=> false, 'peer_fingerprint' => null]]);
  34. $sock = stream_socket_client($serverUri, $errno, $errstr, 30, $clientFlags, $ctx);
  35. var_dump($sock);
  36. $ctx = stream_context_create(['ssl' => ['verify_peer'=> false, 'peer_fingerprint' => []]]);
  37. $sock = stream_socket_client($serverUri, $errno, $errstr, 30, $clientFlags, $ctx);
  38. var_dump($sock);
  39. $ctx = stream_context_create(['ssl' => ['verify_peer'=> false, 'peer_fingerprint' => ['foo']]]);
  40. $sock = stream_socket_client($serverUri, $errno, $errstr, 30, $clientFlags, $ctx);
  41. var_dump($sock);
  42. CODE;
  43. include 'CertificateGenerator.inc';
  44. $certificateGenerator = new CertificateGenerator();
  45. $certificateGenerator->saveNewCertAsFileWithKey('bug68920', $certFile);
  46. include 'ServerClientTestCase.inc';
  47. ServerClientTestCase::getInstance()->run($clientCode, $serverCode);
  48. ?>
  49. --CLEAN--
  50. <?php
  51. @unlink(__DIR__ . DIRECTORY_SEPARATOR . 'bug68920.pem.tmp');
  52. ?>
  53. --EXPECTF--
  54. Warning: stream_socket_client(): Expected peer fingerprint must be a string or an array in %s on line %d
  55. Warning: stream_socket_client(): Failed to enable crypto in %s on line %d
  56. Warning: stream_socket_client(): Unable to connect to %s (Unknown error) in %s on line %d
  57. bool(false)
  58. Warning: stream_socket_client(): Expected peer fingerprint must be a string or an array in %s on line %d
  59. Warning: stream_socket_client(): Failed to enable crypto in %s on line %d
  60. Warning: stream_socket_client(): Unable to connect to %s (Unknown error) in %s on line %d
  61. bool(false)
  62. Warning: stream_socket_client(): Invalid peer_fingerprint array; [algo => fingerprint] form required in %s on line %d
  63. Warning: stream_socket_client(): peer_fingerprint match failure in %s on line %d
  64. Warning: stream_socket_client(): Failed to enable crypto in %s on line %d
  65. Warning: stream_socket_client(): Unable to connect to %s (Unknown error) in %s on line %d
  66. bool(false)
  67. Warning: stream_socket_client(): Invalid peer_fingerprint array; [algo => fingerprint] form required in %s on line %d
  68. Warning: stream_socket_client(): peer_fingerprint match failure in %s on line %d
  69. Warning: stream_socket_client(): Failed to enable crypto in %s on line %d
  70. Warning: stream_socket_client(): Unable to connect to %s (Unknown error) in %s on line %d
  71. bool(false)