Bug #61285 [Opn]: SSL connections do not timeout

From: Date: Mon, 21 Jan 2013 09:16:11 +0000
Subject: Bug #61285 [Opn]: SSL connections do not timeout
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-176144@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=61285&edit=1

 ID:                 61285
 Updated by:         tony2001@php.net
 Reported by:        tony2001@php.net
 Summary:            SSL connections do not timeout
 Status:             Open
 Type:               Bug
 Package:            OpenSSL related
 PHP Version:        5.4SVN-2012-03-05 (SVN)
 Block user comment: N
 Private report:     N

 New Comment:

Uhm.. for some reason Github shows a lot of whitespace changes there.
Could you try to rewrite the patch to avoid them?


Previous Comments:
------------------------------------------------------------------------
[2013-01-20 18:38:01] bbroerman at bbroerman dot net

I have a proposed fix on my Github repo: https://github.com/bbroerman30/php-src

I have tested timeouts of various amounts with blocking sockets, but haven't tried to check
other side-effects as of yet. 

How it works is within the read/write methods themselves, if the socket is blocking and has a
timeout set, it will change the socket (temporarily) to non-blocking, and check the response from
the attempted read/write with SSL_get_error and then wait/retry based on the response from
SSL_get_error and using php_pollfd_for.

When I get a chance (probably next week or so) I'll try to test the below bug, and test with
non-blocking streams.

Please feel free to test as you need, and let me know if you find any bugs.

------------------------------------------------------------------------
[2012-03-05 12:37:02] pajoye@php.net

I am not sure anymore that this patch is correct as it looks as it will 
reintroduce the issue introduced by a previous attempt to fix that, which was 
reverted here:

http://svn.php.net/viewvc?view=revision&revision=315310

------------------------------------------------------------------------
[2012-03-05 12:08:40] tony2001@php.net

The following patch has been added/updated:

Patch Name: ssl_timeout.diff
Revision:   1330949320
URL:        https://bugs.php.net/patch-display.php?bug=61285&patch=ssl_timeout.diff&revision=1330949320

------------------------------------------------------------------------
[2012-03-05 12:08:11] tony2001@php.net

Description:
------------
SSL connections never timeout because poll() isn't even used in ext/openssl.


Test script:
---------------
server.php:
<?php sleep(20); ?>

client.php:
<?php ini_set('default_socket_timeout',1); var_dump(file_get_contents("https://localhost/server.php")); ?>




Expected result:
----------------
# time php client.php

Warning: file_get_contents(https://localhost/server.php): failed to open stream: HTTP request
failed!  in /tmp/client.php on line 1
bool(false)

real    0m2.024s
user    0m0.012s
sys     0m0.003s


Actual result:
--------------
# time php client.php
string(0) ""

real    0m20.063s
user    0m0.012s
sys     0m0.005s


------------------------------------------------------------------------



-- 
Edit this bug report at https://bugs.php.net/bug.php?id=61285&edit=1


Thread (13 messages)

« previous php.bugs (#176144) next »