Bug #53611 [Com]: fastcgi_param PHP_VALUE pollutes other sites

From: Date: Wed, 24 Sep 2014 19:47:56 +0000
Subject: Bug #53611 [Com]: fastcgi_param PHP_VALUE pollutes other sites
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187691@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=53611&edit=1 ID: 53611 Comment by: manuel-php at mausz dot at Reported by: jraxis at gmail dot com Summary: fastcgi_param PHP_VALUE pollutes other sites Status: Re-Opened Type: Bug Package: FPM related Operating System: Linux PHP Version: 5.5.0 Assigned To: fat Block user comment: N Private report: N New Comment: During migration from mod_php to FPM we stumbled across this too. So I've written a small patch which uses Zend INI to restore the altered INI settings after each request: diff -Naur php-5.5.16.orig/sapi/fpm/fpm/fpm_main.c php-5.5.16/sapi/fpm/fpm/fpm_main.c --- php-5.5.16.orig/sapi/fpm/fpm/fpm_main.c 2014-08-21 10:45:02.000000000 +0200 +++ php-5.5.16/sapi/fpm/fpm/fpm_main.c 2014-09-15 16:05:27.777482784 +0200 @@ -1405,7 +1405,6 @@ int *mode = (int *)arg; char *key; char *value = NULL; - struct key_value_s kv; if (!mode || !arg1) return; @@ -1416,7 +1415,7 @@ key = Z_STRVAL_P(arg1); - if (!key || strlen(key) < 1) { + if (!key || Z_STRLEN_P(arg1) < 1) { zlog(ZLOG_ERROR, "Passing INI directive through FastCGI: empty key"); return; } @@ -1430,10 +1429,7 @@ return; } - kv.key = key; - kv.value = value; - kv.next = NULL; - if (fpm_php_apply_defines_ex(&kv, *mode) == -1) { + if (zend_alter_ini_entry(key, Z_STRLEN_P(arg1) + 1, value, Z_STRLEN_P(arg2), *mode, PHP_INI_STAGE_HTACCESS) == FAILURE) { zlog(ZLOG_ERROR, "Passing INI directive through FastCGI: unable to set '%s'", key); } } Previous Comments: ------------------------------------------------------------------------ [2013-11-19 17:24:08] andy at propcom dot co dot uk I have also experienced this. It seems that any ini settings changed with PHP_VALUE or PHP_ADMIN_VALUE environment variables are set for the life of the worker thread by fpm_php_zend_ini_alter_master. Perhaps the old values of the altered settings could be saved and restored on request completion? ------------------------------------------------------------------------ [2013-11-19 17:11:35] andy at propcom dot co dot uk Related To: Bug #63965 ------------------------------------------------------------------------ [2013-10-21 11:06:17] notvalid at example dot com I've also experienced this, but only once during my initial php-fpm setup. It seems it may be related to graceful reconfiguration or FD re-use as I've not experienced it since stabilizing the configs. It was rather worrisome as due to the values I was passing (php_admin_value open_basedir, disable_functions, etc), the site that received the polluted values ceased to function. ------------------------------------------------------------------------ [2013-07-08 23:04:53] yohgaki@php.net I think this is applicable to any versions. Updated version and re-opened. ------------------------------------------------------------------------ [2013-04-03 23:29:40] steven at flechamobile dot com Hi, I can confirm the bug, I have the same issue. I have Nginx with php5-fpm as multi vhost (using sites-enabled & sites-available structure) for one of my sites I have: location ~ \.php$ { try_files $uri =404; fastcgi_split_path_info ^(.+\.php)(/.+)$; include fastcgi_params; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param PHP_VALUE "include_path=/path/to/includes"; fastcgi_pass 127.0.0.1:9000; } Now my other vhost website (other url) with the same conf setup but minus the fastcgi_param PHP_VALUE "include_path=/path/to/includes"; line is searching for includes at the exact same place instead of locally. I'm running Debian 6, nginx + php5-fpm + xcache (+ memcache + memcached). What files do you need for further investigation? fpm conf: ;;;;;;;;;;;;;;;;;;;;; ; FPM Configuration ; ;;;;;;;;;;;;;;;;;;;;; ; All relative paths in this configuration file are relative to PHP's install ; prefix (/usr). This prefix can be dynamicaly changed by using the ; '-p' argument from the command line. ; Include one or more files. If glob(3) exists, it is used to include a bunch of ; files from a glob(3) pattern. This directive can be used everywhere in the ; file. ; Relative path can also be used. They will be prefixed by: ; - the global prefix if it's been set (-p arguement) ; - /usr otherwise ;include=/etc/php5/fpm/*.conf ;;;;;;;;;;;;;;;;;; ; Global Options ; ;;;;;;;;;;;;;;;;;; [global] ; Pid file ; Note: the default prefix is /var ; Default Value: none pid = /var/run/php5-fpm.pid ; Error log file ; If it's set to "syslog", log is sent to syslogd instead of being written ; in a local file. ; Note: the default prefix is /var ; Default Value: log/php-fpm.log error_log = /var/log/php5-fpm.log ; syslog_facility is used to specify what type of program is logging the ; message. This lets syslogd specify that messages from different facilities ; will be handled differently. ; See syslog(3) for possible values (ex daemon equiv LOG_DAEMON) ; Default Value: daemon ;syslog.facility = daemon ; syslog_ident is prepended to every message. If you have multiple FPM ; instances running on the same server, you can change the default value ; which must suit common needs. ; Default Value: php-fpm ;syslog.ident = php-fpm ; Log level ; Possible Values: alert, error, warning, notice, debug ; Default Value: notice ;log_level = notice ; If this number of child processes exit with SIGSEGV or SIGBUS within the time ; interval set by emergency_restart_interval then FPM will restart. A value ; of '0' means 'Off'. ; Default Value: 0 emergency_restart_threshold = 10 ; Interval of time used by emergency_restart_interval to determine when ; a graceful restart will be initiated. This can be useful to work around ; accidental corruptions in an accelerator's shared memory. ; Available Units: s(econds), m(inutes), h(ours), or d(ays) ; Default Unit: seconds ; Default Value: 0 emergency_restart_interval = 1m ; Time limit for child processes to wait for a reaction on signals from master. ; Available units: s(econds), m(inutes), h(ours), or d(ays) ; Default Unit: seconds ; Default Value: 0 process_control_timeout = 10s ; The maximum number of processes FPM will fork. This has been design to control ; the global number of processes when using dynamic PM within a lot of pools. ; Use it with caution. ; Note: A value of 0 indicates no limit ; Default Value: 0 ; process.max = 128 ; Specify the nice(2) priority to apply to the master process (only if set) ; The value can vary from -19 (highest priority) to 20 (lower priority) ; Note: - It will only work if the FPM master process is launched as root ; - The pool process will inherit the master process priority ; unless it specified otherwise ; Default Value: no set ; process.priority = -19 ; Send FPM to background. Set to 'no' to keep FPM in foreground for debugging. ; Default Value: yes ;daemonize = yes ; Set open file descriptor rlimit for the master process. ; Default Value: system defined value ;rlimit_files = 1024 ; Set max core size rlimit for the master process. ; Possible Values: 'unlimited' or an integer greater or equal to 0 ; Default Value: system defined value ;rlimit_core = 0 ; Specify the event mechanism FPM will use. The following is available: ; - select (any POSIX os) ; - poll (any POSIX os) ; - epoll (linux >= 2.5.44) ; - kqueue (FreeBSD >= 4.1, OpenBSD >= 2.9, NetBSD >= 2.0) ; - /dev/poll (Solaris >= 7) ; - port (Solaris >= 10) ; Default Value: not set (auto detection) ; events.mechanism = epoll ;;;;;;;;;;;;;;;;;;;; ; Pool Definitions ; ;;;;;;;;;;;;;;;;;;;; ; Multiple pools of child processes may be started with different listening ; ports and different management options. The name of the pool will be ; used in logs and stats. There is no limitation on the number of pools which ; FPM can handle. Your system will tell you anyway :) ; To configure the pools it is recommended to have one .conf file per ; pool in the following directory: include=/etc/php5/fpm/pool.d/*.conf ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=53611 -- Edit this bug report at https://bugs.php.net/bug.php?id=53611&edit=1

« previous php.bugs (#187691) next »