Bug #68046 [Asn]: 5.5.17 breaks mysqlnd + SSL again

From: Date: Mon, 22 Sep 2014 15:42:10 +0000
Subject: Bug #68046 [Asn]: 5.5.17 breaks mysqlnd + SSL again
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187657@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68046&edit=1 ID: 68046 User updated by: spam2 at rhsoft dot net Reported by: spam2 at rhsoft dot net Summary: 5.5.17 breaks mysqlnd + SSL again Status: Assigned Type: Bug Package: MySQLi related Operating System: Linux PHP Version: 5.5.17 Assigned To: rdlowrey Block user comment: N Private report: N New Comment: > Complaining is being part of the problem > Contributing is being part of the solution oh yeah the next time i don't open a bugreport, just delete the new built RPM and go my way because i can't offer a auto-test matching the upstream codebase but is not much more than a one liner i hestitate to express what i really think about such respones Previous Comments: ------------------------------------------------------------------------ [2014-09-22 15:34:01] rdlowrey@php.net Please submit a PR if you think you have something useful to contribute to the project instead of trying to push it off on other people. Complaining is being part of the problem. Contributing is being part of the solution. Thanks for your time. ------------------------------------------------------------------------ [2014-09-22 15:30:45] spam2 at rhsoft dot net how often do i need to post how to test this? what do you do with a pull-request of a code using our own rwapper around mysqli? http://php.net/manual/de/mysqli.ssl-set.php mysqli_ssl_set ($link, $key, $cert, $ca, NULL, NULL) runs into a timeout ------------------------------------------------------------------------ [2014-09-22 15:22:51] rdlowrey@php.net This is actually not a mysqli issue -- it's an openssl streams issue and has to do with feof() never reporting as true when it should (which causes the script to hang indefinitely). However, any test cases you feel would help can certainly be added. Please submit pull requests via the git account and I will happily merge them. ------------------------------------------------------------------------ [2014-09-22 15:18:06] spam2 at rhsoft dot net there is a simple test i wrote years ago when it was broken the first time * just create certificates * configure mysqld with them * the $this below is only a wrapper which can switch layers * ssl_set() is just the native function $this->ssl_key = '/etc/mysql-ssl/client.pem'; $this->ssl_crt = '/etc/mysql-ssl/client.pem'; $this->ssl_ca = '/etc/mysql-ssl/ca.crt'; $this->conn->ssl_set($this->ssl_key, $this->ssl_crt, $this->ssl_ca, NULL, NULL); ------------------------------------------------------------------------ [2014-09-22 15:07:56] rdlowrey@php.net Yes, we know about this. It was addressed on the mailing list within a couple of hours of the 5.5.17 and 5.4.33 releases. People *do* care about a regression like this. This issue results from trying to fix the DoS vulnerability here: https://bugs.php.net/bug.php?id=41631 Part of the problem is that the streams API has exactly zero test cases and the openssl streams have very few. So when we try to fix one bug there is always the potential to cause another that isn't prevented by preexisting tests. There are volunteers working to improve these aspects of the php-src codebase to help avoid these issues going forward, but it just takes time. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68046 -- Edit this bug report at https://bugs.php.net/bug.php?id=68046&edit=1

« previous php.bugs (#187657) next »