Skip to content

Stdlib: hash_pbkdf2() negative $length — ValueError cites $algo not $length (ext/hash/hash.c) #13417

Description

@PurHur

Category

stdlib · php-src-strict

Problem

hash_pbkdf2() validates $iterations and $length with php-src ValueError messages. VM rejects negative $length with the wrong argument in the message (and may take the wrong validation path).

Call Zend 8.2 VM (today)
hash_pbkdf2('sha256', 'p', 's', 1, -1) ValueError: … Argument #5 ($length) must be greater than or equal to 0 ValueError: … Argument #1 ($algo) must be a valid cryptographic hashing algorithm ❌
hash_pbkdf2('sha256', 'p', 's', 0, 32) / -1 iterations ValueError on $iterations ✓ (message OK)

php-src reference

PHP implementation target

  • ext/hash/hash_pbkdf2.php (or equivalent) — validate $length before/alongside algo lookup; reuse shared ValueError strings from php-src
  • PHP-in-PHP first — no new C in runtime/

Repro (verified 2026-06-29)

php test/repro/maintainer_gap_hash_pbkdf2_iterations_valueerror.php          # ok
php bin/vm.php test/repro/maintainer_gap_hash_pbkdf2_iterations_valueerror.php  # fail

Done when (php-src-strict)

  • Negative/zero $iterations and negative $length throw php-src ValueError messages on the correct argument numbers
  • Compliance guard test/compliance/cases/stdlib/hash_pbkdf2_valueerror.phpt

Verification

php bin/vm.php test/repro/maintainer_gap_hash_pbkdf2_iterations_valueerror.php

Links

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:vmVirtual machineenhancementNew feature or requestimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claimphase-4:stdlibPhase 4 – stdlib for web appsstdlib

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions