Skip to content

ext/openssl: Defer pkcs7/cms verify output writes until verification succeeds - #65

Closed
iliaal wants to merge 1 commit into
PHP-8.4from
fix/openssl-ss004-pre-verify-truncation
Closed

iliaal wants to merge 1 commit into
PHP-8.4from
fix/openssl-ss004-pre-verify-truncation

Conversation

@iliaal

@iliaal iliaal commented May 13, 2026

Copy link
Copy Markdown
Owner

openssl_pkcs7_verify() and openssl_cms_verify() opened their $content and $output_filename paths in write mode before verifying, emptying pre-existing files on verify failure. Dataout now buffers in an in-memory BIO during verify, success opens the destination and copies the verified bytes out, failure touches no file, and the p7bout open defers into the success branch after the signers section, creating the p7b only when the PKCS7/CMS structure will actually be written. Memory-BIO buffering stays bounded by the verified content, typically small for envelopes.

@iliaal
iliaal force-pushed the fix/openssl-ss004-pre-verify-truncation branch from 05ab82f to 4cf1136 Compare September 10, 2026 22:10
…succeeds

openssl_pkcs7_verify() and openssl_cms_verify() opened the content and
p7b output paths in write mode before verify, emptying existing files
when verification failed. Buffer verified content in a memory BIO and
write it only on success; open the p7b path only in that same success
branch. Sibling audit: both verify functions shared the same early-open
pattern; sign/encrypt paths already write after success.
@iliaal
iliaal force-pushed the fix/openssl-ss004-pre-verify-truncation branch from 4cf1136 to 15ae602 Compare September 10, 2026 22:12
@iliaal

iliaal commented Sep 10, 2026

Copy link
Copy Markdown
Owner Author

Upstream: php#23651

@iliaal iliaal closed this Sep 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant