Bug #41631 [Com]: default_socket_timeout does not work with SSL

From: Date: Fri, 19 Sep 2014 15:15:24 +0000
Subject: Bug #41631 [Com]: default_socket_timeout does not work with SSL
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187605@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=41631&edit=1

 ID:                 41631
 Comment by:         rdlowrey@php.net
 Reported by:        david at acz dot org
 Summary:            default_socket_timeout does not work with SSL
 Status:             Re-Opened
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   *
 PHP Version:        5.2, 5.3, 5.4, 5.5, 5.6
 Assigned To:        rdlowrey
 Block user comment: N
 Private report:     N

 New Comment:

I've added a patch that I believe will resolve this issue once and for all. It will apply
directly to 5.4 and 5.5. As this bug is exceedingly difficult to test for in isolation I need
someone to build php with this patch applied and verify that it resolves the Horde problem.

I will wait for feedback before merging this upstream. Thanks.


Previous Comments:
------------------------------------------------------------------------
[2014-09-19 15:13:41] rdlowrey@php.net

The following patch has been added/updated:

Patch Name: bug41631.patch
Revision:   1411139621
URL:        https://bugs.php.net/patch-display.php?bug=41631&patch=bug41631.patch&revision=1411139621

------------------------------------------------------------------------
[2014-09-19 11:05:57] arhimede at gmail dot com

The fix make the bundled Horde on Plesk 11.5, Centos 6.5 useless

Horde/Imap/Client/Socket/Connection/Socket.php
line 116 
feof($this->_stream)  used to return TRUE, now is returning false

------------------------------------------------------------------------
[2014-09-09 16:41:35] rdlowrey@php.net

This issue should now be resolved via 3728449 which will make its way into the next round of bugfix
releases:

https://github.com/php/php-src/commit/372844918a318ad712e16f9ec636682424a65403

------------------------------------------------------------------------
[2014-08-27 15:03:52] rdlowrey@php.net

It seems there is a minor issue with the original fix as outlined in this thread:

https://github.com/php/php-src/commit/6569db88081562f68a4f79e52cba83482bdf05fc

I'll update this issue once resolved.

------------------------------------------------------------------------
[2014-08-07 18:49:34] rdlowrey@php.net

@arkadi Yes, it's unfortunate but the openssl docs are often unclear on details. As far as I
can tell from the relevant openssl source code in the current master branch this should be a
non-issue. In the case you mention it appears that SSL_read will simply return the WANT_READ state,
not block indefinitely. The initial problem was due to PHP blindly assuming there was data to be
read on the socket before launching into a blocking read operation that wouldn't return until
*something* was available to consume.

It should be noted that this scenario is a non-issue in non-blocking applications where an fread()
on the encrypted stream would only be attempted when data is known to be available. The https:// stream wrapper, though, is fully blocking.

References:

https://github.com/openssl/openssl/blob/master/ssl/ssl_lib.c#L1006
https://github.com/openssl/openssl/blob/master/ssl/bio_ssl.c#L140

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=41631


--
Edit this bug report at https://bugs.php.net/bug.php?id=41631&edit=1


Thread (67 messages)

« previous php.bugs (#187605) next »