Req #66208 [Wfx]: PHP-FPM Bind to address

From: Date: Sat, 30 Nov 2013 15:32:23 +0000
Subject: Req #66208 [Wfx]: PHP-FPM Bind to address
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183031@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66208&edit=1

 ID:                 66208
 Updated by:         requinix@php.net
 Reported by:        tronox at hotmail dot com
 Summary:            PHP-FPM Bind to address
 Status:             Wont fix
 Type:               Feature/Change Request
 Package:            *Network Functions
 Operating System:   Amazon AMI
 PHP Version:        5.5.6
 Block user comment: N
 Private report:     N

 New Comment:

Keeping in mind that the SERVER_ADDR is not calculated by PHP (heck, it's not even part of the
CGI standard), yes the SERVER_ADDR does reflect the interface through which the request came, but
that interface is not necessarily one that can access another location.

A very typical development setup is a web server running and listening on localhost: attempting to
access www.example.com from such a server could fail as PHP would try to bind to 127.0.0.1:0
(something that Ubuntu considers an "invalid argument"). Even if it did bind successfully
that interface is useless for connections to anywhere except the machine itself. So okay, so then we
make PHP ignore 127.* addresses and not attempt to bind at all should that be the REMOTE_ADDR?

Now consider the situation where a server sits between the LAN and WAN. That's two (not
counting loopback) interfaces. Traffic from the WAN would allow for connections to www.example.com
as that interface has a route to that host, but traffic from the LAN would fail because it does not.
For PHP to know better it would have to be aware of the system's routing tables, and
that's just becoming too much work - work that the OS does deliberately and automatically for
us anyways.

The current default behavior of PHP, which is to use the default behavior in socket programming (ie,
letting the operating system decide), works perfectly well for nearly all use cases; for those like
you in unusual circumstances (I'm not even sure why you care about which interface is used for
the connection so long as it works) the workaround of stream contexts and "bindto" does
the job quickly and easily.

All that aside, it sounds like your real problem is that the boxes aren't using the right
interfaces for the right destinations, and that's totally something that should be solved with
the network configuration on the machines themselves.


Previous Comments:
------------------------------------------------------------------------
[2013-11-30 09:50:35] tronox at hotmail dot com

More specifically to your exact words:
"talking about the IP address that remote servers see your HTTP requests coming from".

------------------------------------------------------------------------
[2013-11-30 09:49:28] tronox at hotmail dot com

http://example.com/whatismyip.php code is:
<?php echo $_SERVER['REMOTE_ADDR'];?>

To explain it a bit better I guess. When I use file_get_contents('http://example.com/whatismyip.php') I get
back the server's eth0 main IP. Rather then the IP, which while using phpinfo(), returned by
_SERVER["SERVER_ADDR"].

Meaning the IP PHP is using to connect outside of the server is being defined by the server's
default IP even though _SERVER["SERVER_ADDR"] is being set differently per host.

Now most of the functions in PHP already support a bindto via stream. However that would mean I
would have to re-write code to bind to specific IPs. Not to mention having to babysit each site to
make sure they were doing that as well.

I see no reason why PHP shouldn't, or at least have an option for it, bind outgoing connections
defaultly to the IP set in _SERVER["SERVER_ADDR"].

------------------------------------------------------------------------
[2013-11-30 09:14:43] requinix@php.net

So wait, are you talking about the IP address that your web server is binding to, which is what your
title and latest reply are talking about (despite how it's not PHP-FPM that does that), or are
you talking about the IP address that remote servers see your HTTP requests coming from, which is
what your description was about?

------------------------------------------------------------------------
[2013-11-30 08:36:35] tronox at hotmail dot com

MANY services out there allow for binding of their outgoing IPs. Even PHP does via scripting. I see
no reason why php can't have a default IP binding setting. This would not only make it possibly
more secure. But it would also support virtual hosting much better.

Making a VPM for every virtual host is a bit much. A Simple chroot suffices for most things packed
with open_basedir. The only remaining issue is what IP clients are using for outgoing connections.
Which opens a whole lot of security issues on a system. IE: I can't block or allow specific IPs
outgoing traffic for specific ports. I can't track traffic usage reliably for a specific IP.

------------------------------------------------------------------------
[2013-11-30 07:39:22] requinix@php.net

A full explanation of why that's not possible is out of the scope of this bug reporting system,
but suffice it to say that's not how networking works.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=66208


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=66208&edit=1


Thread (12 messages)

« previous php.bugs (#183031) next »