#39571 [Opn->Bgs]: fsockopen timeout param does not affect ssl/tls handshake

From: Date: Sat, 02 Dec 2006 17:04:12 +0000
Subject: #39571 [Opn->Bgs]: fsockopen timeout param does not affect ssl/tls handshake
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-105798@lists.php.net to get a copy of this message
ID: 39571 Updated by: iliaa@php.net Reported By: tim at tmcode dot com -Status: Open +Status: Bogus Bug Type: Sockets related Operating System: Linux PHP Version: 5CVS-2006-11-21 (CVS) New Comment: Sorry, but your problem does not imply a bug in PHP itself. For a list of more appropriate places to ask for help using PHP, please visit http://www.php.net/support.php as this bug system is not the appropriate forum for asking support questions. Due to the volume of reports we can not explain in detail here why your report is not a bug. The support channels will be able to provide an explanation for you. Thank you for your interest in PHP. It would be one thing to use SSL function or parameter to enforce the timeout, but what you suggest seems like a hack (that may have many stability side-effects) to overcome limitation of the underlying library. My suggestion would be to make a feature request to the OpenSSL folks to add a timeout parameter and once it is there, PHP will certainly use it with the supported version of the lib. Previous Comments: ------------------------------------------------------------------------ [2006-11-21 18:04:57] tim at tmcode dot com Heh, no way to support timeouts with openssl? Now thats funny. :) The problem is with SSL_connect() on line 400 of ext/openssl/xp_ssl.c All you have to do is throw the socket into nonblocking mode. Then loop until the timeout has been reached or SSL_connect returns >0. The socket can then be placed back in blocking mode. I have a very quick and dirty patch that does this. Unfortunately it relies on fcntl() so I'm not sure how well it would port off of *nix. If it would help get the bug fixed I would be happy to provide it. ------------------------------------------------------------------------ [2006-11-21 17:16:36] tony2001@php.net There is no way to set a timeout on SSL operations which do not support it. ------------------------------------------------------------------------ [2006-11-21 16:23:54] tim at tmcode dot com Description: ------------ The 5th parameter of the fsockopen function does not appear to account for a webserver taking too long to complete the ssl/tls handshake. When connecting to an extremely loaded server, the connection might establish within the timeout but the ssl handshake could take much longer. From what I can tell there is no way to set the read/write timeout prior to running fsockopen, making it impossible to prevent PHP from hanging on a slow ssl server? (I tried to find a similar bug or a mention of this issue in the manual so I appologize if I need to go RTFM more carefully). This problem only affects fsockopen if you use ssl:// or tls:// in the first param. If you modifiy the code below and just remove the ssl:// the function call works fine. Reproduce code: --------------- // client code: $fp = fsockopen("ssl://$server", 443, $errno, $errstr, 5); If you want to simulate a "hung" ssl server to verify that the timeout does not happen in 5 seconds: // server code: $sock=socket_create(AF_INET,SOCK_STREAM,SOL_TCP); if(!socket_bind($sock,$serverip,443)) die("bind\n"); if(!socket_listen($sock,25)) die("listen\n"); if(!socket_set_nonblock($sock)) die("nonblock\n"); while(1) { $newfd=@socket_accept($sock); sleep(30); } Expected result: ---------------- fsockopen should timeout after 5 seconds. Actual result: -------------- fsockopen times out after 58 seconds (with the test server code above). Change sleep to something larger and the timeout will take even longer. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=39571&edit=1

« previous php.bugs (#105798) next »