Bug #66611 [Com]: php allows sockets to be inherited
| From: | glen at delfi dot ee | Date: | Fri, 31 Jan 2014 20:09:39 +0000 |
| Subject: | Bug #66611 [Com]: php allows sockets to be inherited | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184106@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66611&edit=1
ID: 66611
Comment by: glen at delfi dot ee
Reported by: arekm at maven dot pl
Summary: php allows sockets to be inherited
Status: Open
Type: Bug
Package: FPM related
Operating System: Linux
PHP Version: 5.5.8
Block user comment: N
Private report: N
New Comment:
https://issues.apache.org/bugzilla/show_bug.cgi?id=46425
Previous Comments:
------------------------------------------------------------------------
[2014-01-31 20:08:31] glen at delfi dot ee
$ svn log -c 747990 https://svn.apache.org/repos/asf|diffcol |less
------------------------------------------------------------------------
r747990 | bojan | 2009-02-26 04:41:21 +0200 (N, 26 veebr 2009) | 7 lines
Set CLOEXEC flags where appropriate. Either use new O_CLOEXEC flag and
associated functions, such as dup3(), accept4(), epoll_create1() etc., or
simply set CLOEXEC flag using fcntl().
Patch by Stefan Fritsch <sf sfritsch.de> and
Arkadiusz Miskiewicz <arekm pld-linux.org>.
PR 46425.
------------------------------------------------------------------------
[2014-01-31 20:06:57] glen at delfi dot ee
that svnweb link opens dead slow, so here's command you can get the diff faster from terminal:
$ svn diff -c 747990 https://svn.apache.org/repos/asf
------------------------------------------------------------------------
[2014-01-30 10:38:49] arekm at maven dot pl
Note, example of similar case (leaking socket/descriptors) in apache apr code and how it got fixed
there:
http://svn.apache.org/viewvc?view=revision&revision=747990
------------------------------------------------------------------------
[2014-01-30 10:37:18] arekm at maven dot pl
Description:
------------
php fcgi and fpm unfortunately allow subprocesses to inherit server socket.
For example, test script:
<?php
system("sleep 1000");
?>
run it using browser over fcgi or fpm, we get:
# pstree -lpu |grep 32686
| `-php55.fcgi(32671)-+-php55.fcgi(32678)---sh(32686)
but now look what descriptors are avilable to "sh" process:
# lsof |grep 32686
[...]
sh 32686 lighttpd 0u unix 0xffff880261a17700 0t0 9572697
/var/run/php/php-fcgi-32664.sock-1
[...]
sh 32686 lighttpd 3u unix 0xffff880261a15e80 0t0 9576285
/var/run/php/php-fcgi-32664.sock-1
as you can see "sleep" has access to fcgi socket! And instead of sleep I could run some
malicious code.
The same happens with tcp socket in case of fpm over tcp. Processes forked from php have access to
server socket 9000.
The solution is to set FD_CLOEXEC (see man fcntl) flag on socket or use proper api (SOCK_CLOEXEC
flag, accept4()).
Note that leaking descriptors/sockets falls into secutity catgory in some cases.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66611&edit=1