Bug #67244 [Com]: Wrong owner:group for listening unix socket
Edit report at https://bugs.php.net/bug.php?id=67244&edit=1
ID: 67244
Comment by: peter dot mescalchin at gmail dot com
Reported by: bugs-php at antipoul dot fr
Summary: Wrong owner:group for listening unix socket
Status: Open
Type: Bug
Package: FPM related
Operating System: Linux
PHP Version: 5.5.12
Block user comment: N
Private report: N
New Comment:
Yeah this is somewhat related to my ticket https://bugs.php.net/bug.php?id=67175 basically the
permissions for the socket have changed from 0666 to 0660 as of 5.5.12.
What I think has been happening in your case:
- The socket was always being created as root:root
- Since the socket WAS 0666 any process could hook into it (e.g. Nginx)
- Now that's no longer the case.
Also the comments around "Default Values: user and group are set as the running user" is a
little confusing - it's NOT the user that the php-fpm childs will run as (user=/group=) but the
user that starts the php-fpm daemon - which if from upstart/init.d/systemd will typically be root
(and a good choice).
In your final example it's working as expected - the default group for the www-data user is
www-data so it's using that. There is zero interaction between (user=/group=) and
(listen.owner=/listen.group=) settings.
In the end this all boils down to improvements in both PHP documentation and comments in
php-fpm.conf. I have submitted a change to the PHP docs (to say that default is 0660 - not committed
yet) - php-fpm.conf has some changes coming for PHP 5.6, but maybe this confusion you have here
could be better explained.
Previous Comments:
------------------------------------------------------------------------
[2014-05-11 07:49:29] bugs-php at antipoul dot fr
Description:
------------
After upgrading to 5.5.12 that fixes #67060, my FPM instances (I have two of them) since to be
unreachable from my nginx web server.
I am using unix socket to communicate between nginx and fpm.
The sockets belong to root:root, which is NOT what is configured:
user = www-data
group = www-data
This are the settings for the running process, but later in the file, it says the following:
; Set permissions for unix socket, if one is used. In Linux, read/write
; permissions must be set in order to allow connections from a web server. Many
; BSD-derived systems allow connections regardless of permissions.
; Default Values: user and group are set as the running user
Unfortunately, sockets are created with root:root ownership.
The workaround is to modify the listen.owner or the listen.group directive.
Moreover, if I have the following configuration:
user = www-data
group = nas
listen.owner = www-data
Then the socket is created with www-data:www-data ownership. This should be www-data:nas
See the www.conf
(https://cloud.antipoul.fr/public.php?service=files&t=d9c210c044dbf507d65aafb9af317090&download)
and cloud.conf
(https://cloud.antipoul.fr/public.php?service=files&t=c14885c0cd990c28ed42672f91b97c3a&download).
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67244&edit=1
Thread (7 messages)