Edit report at https://bugs.php.net/bug.php?id=65137&edit=1
ID: 65137
Updated by: daverandom@php.net
Reported by: boen dot robot at gmail dot com
Summary: stream_select misleads when TLS socket is used
-Status: Feedback
+Status: Closed
Type: Bug
Package: Streams related
Operating System: Windows Server 2008 R2
PHP Version: 5.5.0
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2014-08-23 01:04:37] daverandom@php.net
This occurs because OpenSSL has an internal buffer, which stream_select() does not inspect.
I've just thrown a patch together [1] which fixes the issue for me, I'm going to try and
squeeze it into 5.4.32, not sure if that ship has sailed yet, it may have to be 5.5+ only as
it's not really a security fix in the strictest sense.
[1] https://github.com/DaveRandom/php-src/compare/fix/ssl-stream-select-buffer
------------------------------------------------------------------------
[2014-04-03 14:49:00] boen dot robot at gmail dot com
To ab@php.net:
Sorry for not responding earlier - and no, I'm not using x64 bins. All bins are the x86 NTS
bins from windows.php.net.
------------------------------------------------------------------------
[2014-04-03 14:27:03] heruan at aldu dot net
This is also happening when a stream_socket_server() accepts a connection and
stream_socket_enable_crypto() on it; then, stream_select() reports data on a read socket but an
immediate fread() returns empty, while usleep() a bit before fread() succeeds. This is happening on
Linux with PHP 5.5.9.
------------------------------------------------------------------------
[2014-01-02 13:28:01] ab@php.net
Are you using x64 bins? There was a fix related to another bug, but the exact place you've
pointed to was touched
http://git.php.net/?p=php-src.git;a=commitdiff;h=da62fd5ed824bafc4dc3e90278c3d57d8e74cbe1
That's most likely a fix on win64, not sure if it'll affect a 32 bit builds in your case.
Anyway, I'd say it makes sense you to test again with a snap from here http://windows.php.net/downloads/snaps/php-5.5/
(please pick the latest). With those snaps and your snippet I get "stream_select() returned
with errors", but also a lot of warnings with display_errors=1. Used some public sites like
SSL'd google, etc.
Thanks.
------------------------------------------------------------------------
[2013-06-26 23:59:08] boen dot robot at gmail dot com
On a quick inspection of the relevant source (and I must note I know nothing about PHP's
internals, nor have I compiled PHP, so take this with a grain of salt), this seems to be the
problematic part:
https://github.com/php/php-src/blob/642721b38a9c5ebf336c81027c0dafd6f9246bd6/ext/openssl/xp_ssl.c#L814
For some reason, when doing a cast for stream_select(), the actual socket is returned directly, as
opposed to this happening after an "sslsock->ssl_active" check, like the other casts,
which I'm guessing is causing the gap between what stream_select() says, and what fread() does.
What's the reason for it being that way anyway?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=65137
--
Edit this bug report at https://bugs.php.net/bug.php?id=65137&edit=1