#39571 [Bgs->Opn]: fsockopen timeout param does not affect ssl/tls handshake

From: Date: Tue, 21 Nov 2006 18:04:57 +0000
Subject: #39571 [Bgs->Opn]: fsockopen timeout param does not affect ssl/tls handshake
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-105263@lists.php.net to get a copy of this message
ID: 39571 User updated by: tim at tmcode dot com Reported By: tim at tmcode dot com -Status: Bogus +Status: Open Bug Type: Sockets related Operating System: Linux PHP Version: 5CVS-2006-11-21 (CVS) New Comment: Heh, no way to support timeouts with openssl? Now thats funny. :) The problem is with SSL_connect() on line 400 of ext/openssl/xp_ssl.c All you have to do is throw the socket into nonblocking mode. Then loop until the timeout has been reached or SSL_connect returns >0. The socket can then be placed back in blocking mode. I have a very quick and dirty patch that does this. Unfortunately it relies on fcntl() so I'm not sure how well it would port off of *nix. If it would help get the bug fixed I would be happy to provide it. Previous Comments: ------------------------------------------------------------------------ [2006-11-21 17:16:36] tony2001@php.net There is no way to set a timeout on SSL operations which do not support it. ------------------------------------------------------------------------ [2006-11-21 16:23:54] tim at tmcode dot com Description: ------------ The 5th parameter of the fsockopen function does not appear to account for a webserver taking too long to complete the ssl/tls handshake. When connecting to an extremely loaded server, the connection might establish within the timeout but the ssl handshake could take much longer. From what I can tell there is no way to set the read/write timeout prior to running fsockopen, making it impossible to prevent PHP from hanging on a slow ssl server? (I tried to find a similar bug or a mention of this issue in the manual so I appologize if I need to go RTFM more carefully). This problem only affects fsockopen if you use ssl:// or tls:// in the first param. If you modifiy the code below and just remove the ssl:// the function call works fine. Reproduce code: --------------- // client code: $fp = fsockopen("ssl://$server", 443, $errno, $errstr, 5); If you want to simulate a "hung" ssl server to verify that the timeout does not happen in 5 seconds: // server code: $sock=socket_create(AF_INET,SOCK_STREAM,SOL_TCP); if(!socket_bind($sock,$serverip,443)) die("bind\n"); if(!socket_listen($sock,25)) die("listen\n"); if(!socket_set_nonblock($sock)) die("nonblock\n"); while(1) { $newfd=@socket_accept($sock); sleep(30); } Expected result: ---------------- fsockopen should timeout after 5 seconds. Actual result: -------------- fsockopen times out after 58 seconds (with the test server code above). Change sleep to something larger and the timeout will take even longer. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=39571&edit=1

« previous php.bugs (#105263) next »