Bug #66611 [Com]: php allows sockets to be inherited

From: Date: Fri, 31 Jan 2014 20:09:39 +0000
Subject: Bug #66611 [Com]: php allows sockets to be inherited
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184106@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66611&edit=1 ID: 66611 Comment by: glen at delfi dot ee Reported by: arekm at maven dot pl Summary: php allows sockets to be inherited Status: Open Type: Bug Package: FPM related Operating System: Linux PHP Version: 5.5.8 Block user comment: N Private report: N New Comment: https://issues.apache.org/bugzilla/show_bug.cgi?id=46425 Previous Comments: ------------------------------------------------------------------------ [2014-01-31 20:08:31] glen at delfi dot ee $ svn log -c 747990 https://svn.apache.org/repos/asf|diffcol |less ------------------------------------------------------------------------ r747990 | bojan | 2009-02-26 04:41:21 +0200 (N, 26 veebr 2009) | 7 lines Set CLOEXEC flags where appropriate. Either use new O_CLOEXEC flag and associated functions, such as dup3(), accept4(), epoll_create1() etc., or simply set CLOEXEC flag using fcntl(). Patch by Stefan Fritsch <sf sfritsch.de> and Arkadiusz Miskiewicz <arekm pld-linux.org>. PR 46425. ------------------------------------------------------------------------ [2014-01-31 20:06:57] glen at delfi dot ee that svnweb link opens dead slow, so here's command you can get the diff faster from terminal: $ svn diff -c 747990 https://svn.apache.org/repos/asf ------------------------------------------------------------------------ [2014-01-30 10:38:49] arekm at maven dot pl Note, example of similar case (leaking socket/descriptors) in apache apr code and how it got fixed there: http://svn.apache.org/viewvc?view=revision&revision=747990 ------------------------------------------------------------------------ [2014-01-30 10:37:18] arekm at maven dot pl Description: ------------ php fcgi and fpm unfortunately allow subprocesses to inherit server socket. For example, test script: <?php system("sleep 1000"); ?> run it using browser over fcgi or fpm, we get: # pstree -lpu |grep 32686 | `-php55.fcgi(32671)-+-php55.fcgi(32678)---sh(32686) but now look what descriptors are avilable to "sh" process: # lsof |grep 32686 [...] sh 32686 lighttpd 0u unix 0xffff880261a17700 0t0 9572697 /var/run/php/php-fcgi-32664.sock-1 [...] sh 32686 lighttpd 3u unix 0xffff880261a15e80 0t0 9576285 /var/run/php/php-fcgi-32664.sock-1 as you can see "sleep" has access to fcgi socket! And instead of sleep I could run some malicious code. The same happens with tcp socket in case of fpm over tcp. Processes forked from php have access to server socket 9000. The solution is to set FD_CLOEXEC (see man fcntl) flag on socket or use proper api (SOCK_CLOEXEC flag, accept4()). Note that leaking descriptors/sockets falls into secutity catgory in some cases. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66611&edit=1

« previous php.bugs (#184106) next »