#39571 [Bgs->Opn]: fsockopen timeout param does not affect ssl/tls handshake
| From: | tim at tmcode dot com | Date: | Tue, 21 Nov 2006 18:04:57 +0000 |
| Subject: | #39571 [Bgs->Opn]: fsockopen timeout param does not affect ssl/tls handshake | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-105263@lists.php.net to get a copy of this message | ||
ID: 39571
User updated by: tim at tmcode dot com
Reported By: tim at tmcode dot com
-Status: Bogus
+Status: Open
Bug Type: Sockets related
Operating System: Linux
PHP Version: 5CVS-2006-11-21 (CVS)
New Comment:
Heh, no way to support timeouts with openssl? Now thats funny. :)
The problem is with SSL_connect() on line 400 of ext/openssl/xp_ssl.c
All you have to do is throw the socket into nonblocking mode. Then
loop until the timeout has been reached or SSL_connect returns >0. The
socket can then be placed back in blocking mode.
I have a very quick and dirty patch that does this. Unfortunately it
relies on fcntl() so I'm not sure how well it would port off of *nix.
If it would help get the bug fixed I would be happy to provide it.
Previous Comments:
------------------------------------------------------------------------
[2006-11-21 17:16:36] tony2001@php.net
There is no way to set a timeout on SSL operations which do not support
it.
------------------------------------------------------------------------
[2006-11-21 16:23:54] tim at tmcode dot com
Description:
------------
The 5th parameter of the fsockopen function does not appear to account
for a webserver taking too long to complete the ssl/tls handshake.
When connecting to an extremely loaded server, the connection might
establish within the timeout but the ssl handshake could take much
longer. From what I can tell there is no way to set the read/write
timeout prior to running fsockopen, making it impossible to prevent
PHP from hanging on a slow ssl server?
(I tried to find a similar bug or a mention of this issue in the manual
so I appologize if I need to go RTFM more carefully).
This problem only affects fsockopen if you use ssl:// or tls:// in the
first param. If you modifiy the code below and just remove the ssl://
the function call works fine.
Reproduce code:
---------------
// client code:
$fp = fsockopen("ssl://$server", 443, $errno, $errstr, 5);
If you want to simulate a "hung" ssl server to verify that the timeout
does not happen in 5 seconds:
// server code:
$sock=socket_create(AF_INET,SOCK_STREAM,SOL_TCP);
if(!socket_bind($sock,$serverip,443)) die("bind\n");
if(!socket_listen($sock,25)) die("listen\n");
if(!socket_set_nonblock($sock)) die("nonblock\n");
while(1)
{
$newfd=@socket_accept($sock);
sleep(30);
}
Expected result:
----------------
fsockopen should timeout after 5 seconds.
Actual result:
--------------
fsockopen times out after 58 seconds (with the test server code above).
Change sleep to something larger and the timeout will take even longer.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=39571&edit=1