Bug #41631 [Com]: default_socket_timeout does not work with SSL

From: Date: Fri, 26 Sep 2014 14:14:07 +0000
Subject: Bug #41631 [Com]: default_socket_timeout does not work with SSL
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187720@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=41631&edit=1

 ID:                 41631
 Comment by:         admin at brandensittich dot de
 Reported by:        david at acz dot org
 Summary:            default_socket_timeout does not work with SSL
 Status:             Re-Opened
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   *
 PHP Version:        5.2, 5.3, 5.4, 5.5, 5.6
 Assigned To:        rdlowrey
 Block user comment: N
 Private report:     N

 New Comment:

This Problem also affects Roundcube Webmail 1.0.2

PHP 5.5.17-1~dotdeb.1 (cli) (built: Sep 19 2014 01:56:56)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies
with Zend OPcache v7.0.4-dev, Copyright (c) 1999-2014, by Zend Technologies


[26-Sep-2014 16:02:55 Europe/Berlin] PHP Warning:  fgets(): SSL read operation timed out in
[...]/program/lib/Roundcube/rcube_imap_generic.php on line 200

    /**
     * Reads line from the connection stream
     *
     * @param int  $size  Buffer size
     *
     * @return string Line of text response
     */
    function readLine($size=1024)
    {
        $line = '';

        if (!$size) {
            $size = 1024;
        }

        do {
            if ($this->eof()) {
                return $line ? $line : NULL;
            }

            // Line 200: SSL read operation timed out
            $buffer = fgets($this->fp, $size);

            if ($buffer === false) {
                $this->closeSocket();
                break;
            }
            if ($this->_debug) {
                $this->debug('S: '. rtrim($buffer));
            }
            $line .= $buffer;
        } while (substr($buffer, -1) != "\n");

        return $line;
    }


Previous Comments:
------------------------------------------------------------------------
[2014-09-26 08:08:00] stas@php.net

Since 5.4 is now in security-fixes mode, and the patch for this issue that got into 5.4.33 was not
good, I have reverted the 5.4 branch to its 5.4.32 status for xp_ssl.c. Please verify ASAP that this
does not cause additional regressions for 5.4. In 5.5, it still stays as it was before and
additional fixes can be applied there if needed.

------------------------------------------------------------------------
[2014-09-24 06:11:13] slusarz at horde dot org

@rdlowery: Thanks for the update.  Given @software-horde report that things are working with Horde
with the most up-to-date patches, that is sufficient confirmation to me that this has been fixed.

Will let people know from a Horde support perspective that they need to either downgrade for now or
wait for the next point release.

------------------------------------------------------------------------
[2014-09-23 05:28:26] rdlowrey@php.net

@slusarz Thanks for your offer to help. It's nothing specific you guys are doing at Horde --
it's a problem with the encrypted stream code in ext/openssl. These issues were mostly fixed
before the releases but due to a miscommunication the relevant commits failed to make it into the
5.4.33 and 5.5.17.

I'm quite sorry these issues made it into release as it has also caused plenty of headaches for
me! Some people are quite rude about these sorts of things and don't seem to realize that
pretty much everyone who works on php-src does so as an unpaid volunteer (myself included). I
definitely appreciate your offer to help. I'll be in touch to let you know as soon as this is
fully resolved and/or to ask you guys to do a quick build from source to verify for sure that your
problems are addressed.

------------------------------------------------------------------------
[2014-09-23 05:06:14] rdlowrey@php.net

Just to clarify, the working patch posted by software-php at interfasys dot ch is a combination of
the patch I posted above with the two commits that were already made to the 5.4 and 5.5 branches but
mistakenly left out of the releases due to a miscommunication. You can see those commits here:

https://github.com/php/php-src/commit/372844918a318ad712e16f9ec636682424a65403
https://github.com/php/php-src/commit/f86b2193a483f56b0bd056570a0cdb57ebe66e2f

These have already been added to the relevant branches.

I would appreciate it if someone could please verify that applying the previously posted patch
(https://bugs.php.net/patch-display.php?bug=41631&patch=bug41631.patch&revision=1411139621)
to the current PHP-5.5 and PHP-5.4 branches of the source code resolves the problem so we can
eliminate several bugs at once instead of reverting everything and starting back from square one.

------------------------------------------------------------------------
[2014-09-22 23:20:36] software-horde at interfasys dot ch

@slusarz, the patch fixed the issue we had with Horde on PHP 5.4.33 :)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=41631


--
Edit this bug report at https://bugs.php.net/bug.php?id=41631&edit=1


Thread (67 messages)

« previous php.bugs (#187720) next »