Category
stdlib · php-src-strict
Problem
hash_pbkdf2() validates $iterations and $length with php-src ValueError messages. VM rejects negative $length with the wrong argument in the message (and may take the wrong validation path).
| Call |
Zend 8.2 |
VM (today) |
hash_pbkdf2('sha256', 'p', 's', 1, -1) |
ValueError: … Argument #5 ($length) must be greater than or equal to 0 |
ValueError: … Argument #1 ($algo) must be a valid cryptographic hashing algorithm ❌ |
hash_pbkdf2('sha256', 'p', 's', 0, 32) / -1 iterations |
ValueError on $iterations |
✓ (message OK) |
php-src reference
PHP implementation target
ext/hash/hash_pbkdf2.php (or equivalent) — validate $length before/alongside algo lookup; reuse shared ValueError strings from php-src
- PHP-in-PHP first — no new C in
runtime/
Repro (verified 2026-06-29)
php test/repro/maintainer_gap_hash_pbkdf2_iterations_valueerror.php # ok
php bin/vm.php test/repro/maintainer_gap_hash_pbkdf2_iterations_valueerror.php # fail
Done when (php-src-strict)
Verification
php bin/vm.php test/repro/maintainer_gap_hash_pbkdf2_iterations_valueerror.php
Links
Category
stdlib· php-src-strictProblem
hash_pbkdf2()validates$iterationsand$lengthwith php-srcValueErrormessages. VM rejects negative$lengthwith the wrong argument in the message (and may take the wrong validation path).hash_pbkdf2('sha256', 'p', 's', 1, -1)ValueError: … Argument #5 ($length) must be greater than or equal to 0ValueError: … Argument #1 ($algo) must be a valid cryptographic hashing algorithm❌hash_pbkdf2('sha256', 'p', 's', 0, 32)/-1iterationsValueErroron$iterationsphp-src reference
ext/hash/hash.c—php_hash_pbkdf2argument validation orderPHP implementation target
ext/hash/hash_pbkdf2.php(or equivalent) — validate$lengthbefore/alongside algo lookup; reuse sharedValueErrorstrings from php-srcruntime/Repro (verified 2026-06-29)
Done when (php-src-strict)
$iterationsand negative$lengththrow php-srcValueErrormessages on the correct argument numberstest/compliance/cases/stdlib/hash_pbkdf2_valueerror.phptVerification
Links