Commit b6cda1f
committed
Verify child process result file with a random nonce
PHPUnit runs isolated tests by having the child process serialize a result object and write it to a temporary file under the system's directory for temporary files. The parent process then reads the file and calls unserialize() on its contents. The serialized payload contains Event, TestResult, PassedTests, and CodeCoverage instances, all types whose constructors and __wakeup() / __destruct() methods execute during deserialization. An attacker who can write to the temporary file between the child's exit and the parent's read can substitute a crafted serialized payload and achieve code execution in the parent PHPUnit process.
This change defends against that write-after-exit race:
* SeparateProcessTestRunner generates a 32-character hex nonce (bin2hex(random_bytes(16))) per isolated test, injects it into the child template as {processResultNonce}, and passes the same value to JobRunnerRegistry::runTestJob().
* The child template prepends the nonce to the serialized payload before writing it to the result file.
* ChildProcessResultProcessor compares the file's prefix against the expected nonce with hash_equals(). A mismatch or short read is treated as tampering: childProcessErrored is emitted, the test is marked errored with an AssertionFailedError, and unserialize() is never called. On a match the prefix is stripped and processing continues as before.
What this blocks:
* A co-tenant on a shared CI runner (or any local process that can write to the temp directory) replacing the result file with a crafted serialized payload between the child's exit and the parent's read. Without the nonce, the payload cannot pass the hash_equals() check and is rejected before reaching unserialize().
* Accidental reuse of a stale result file from an unrelated process that happens to occupy the same temp path.
What this does not block:
* A compromised or attacker-controlled child process. The child must know the nonce in order to emit a valid result, so any code running inside the child (including malicious test code executed by an untrusted pull request on an unisolated CI job) can produce a payload that passes the prefix check. Closing that vector requires converting the wire format away from serialize() of live objects.
* Attacks that do not involve swapping the result file, such as exploiting bugs in the Event subsystem itself once a legitimate payload has been deserialized.
The nonce is a defence-in-depth measure against the local race, not a substitute for treating the serialized wire format as untrusted input.1 parent e130965 commit b6cda1f
File tree
7 files changed
+102
-9
lines changed- src
- Framework/TestRunner
- templates
- Util/PHP
- tests/unit/Framework/TestRunner
7 files changed
+102
-9
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
13 | 16 | | |
14 | 17 | | |
15 | 18 | | |
| |||
37 | 40 | | |
38 | 41 | | |
39 | 42 | | |
40 | | - | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
41 | 47 | | |
42 | 48 | | |
43 | 49 | | |
| |||
52 | 58 | | |
53 | 59 | | |
54 | 60 | | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
55 | 90 | | |
56 | 91 | | |
57 | 92 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
13 | 14 | | |
14 | 15 | | |
15 | 16 | | |
| 17 | + | |
16 | 18 | | |
17 | 19 | | |
18 | 20 | | |
| |||
118 | 120 | | |
119 | 121 | | |
120 | 122 | | |
| 123 | + | |
121 | 124 | | |
122 | 125 | | |
123 | 126 | | |
| |||
144 | 147 | | |
145 | 148 | | |
146 | 149 | | |
| 150 | + | |
147 | 151 | | |
148 | 152 | | |
149 | 153 | | |
| |||
157 | 161 | | |
158 | 162 | | |
159 | 163 | | |
160 | | - | |
| 164 | + | |
161 | 165 | | |
162 | 166 | | |
163 | 167 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
104 | 104 | | |
105 | 105 | | |
106 | 106 | | |
107 | | - | |
| 107 | + | |
108 | 108 | | |
109 | 109 | | |
110 | 110 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
104 | 104 | | |
105 | 105 | | |
106 | 106 | | |
107 | | - | |
| 107 | + | |
108 | 108 | | |
109 | 109 | | |
110 | 110 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
63 | | - | |
| 63 | + | |
| 64 | + | |
64 | 65 | | |
65 | | - | |
| 66 | + | |
66 | 67 | | |
67 | 68 | | |
68 | 69 | | |
| |||
80 | 81 | | |
81 | 82 | | |
82 | 83 | | |
| 84 | + | |
83 | 85 | | |
84 | 86 | | |
85 | 87 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
33 | | - | |
| 33 | + | |
| 34 | + | |
34 | 35 | | |
35 | | - | |
| 36 | + | |
36 | 37 | | |
37 | | - | |
| 38 | + | |
38 | 39 | | |
39 | 40 | | |
40 | 41 | | |
| |||
Lines changed: 51 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
46 | 46 | | |
47 | 47 | | |
48 | 48 | | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
49 | 100 | | |
50 | 101 | | |
51 | 102 | | |
| |||
0 commit comments