Bug #41631 [Com]: default_socket_timeout does not work with SSL

From: Date: Fri, 26 Sep 2014 18:43:08 +0000
Subject: Bug #41631 [Com]: default_socket_timeout does not work with SSL
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187723@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=41631&edit=1

 ID:                 41631
 Comment by:         askalski at synacor dot com
 Reported by:        david at acz dot org
 Summary:            default_socket_timeout does not work with SSL
 Status:             Re-Opened
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   *
 PHP Version:        5.2, 5.3, 5.4, 5.5, 5.6
 Assigned To:        rdlowrey
 Block user comment: N
 Private report:     N

 New Comment:

I attached a locally-maintained patch for this bug that we've been running in production for
the past 3 years.  I'm curious to know if this version of the fix works with Horde?


Previous Comments:
------------------------------------------------------------------------
[2014-09-26 15:37:36] software-php at interfasys dot ch

Even after the patches were applied, Horde could not connect to the sieve server (4190) using TLS,
so something is still very wrong.

------------------------------------------------------------------------
[2014-09-26 14:14:04] admin at brandensittich dot de

This Problem also affects Roundcube Webmail 1.0.2

PHP 5.5.17-1~dotdeb.1 (cli) (built: Sep 19 2014 01:56:56)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies
with Zend OPcache v7.0.4-dev, Copyright (c) 1999-2014, by Zend Technologies


[26-Sep-2014 16:02:55 Europe/Berlin] PHP Warning:  fgets(): SSL read operation timed out in
[...]/program/lib/Roundcube/rcube_imap_generic.php on line 200

    /**
     * Reads line from the connection stream
     *
     * @param int  $size  Buffer size
     *
     * @return string Line of text response
     */
    function readLine($size=1024)
    {
        $line = '';

        if (!$size) {
            $size = 1024;
        }

        do {
            if ($this->eof()) {
                return $line ? $line : NULL;
            }

            // Line 200: SSL read operation timed out
            $buffer = fgets($this->fp, $size);

            if ($buffer === false) {
                $this->closeSocket();
                break;
            }
            if ($this->_debug) {
                $this->debug('S: '. rtrim($buffer));
            }
            $line .= $buffer;
        } while (substr($buffer, -1) != "\n");

        return $line;
    }

------------------------------------------------------------------------
[2014-09-26 08:08:00] stas@php.net

Since 5.4 is now in security-fixes mode, and the patch for this issue that got into 5.4.33 was not
good, I have reverted the 5.4 branch to its 5.4.32 status for xp_ssl.c. Please verify ASAP that this
does not cause additional regressions for 5.4. In 5.5, it still stays as it was before and
additional fixes can be applied there if needed.

------------------------------------------------------------------------
[2014-09-24 06:11:13] slusarz at horde dot org

@rdlowery: Thanks for the update.  Given @software-horde report that things are working with Horde
with the most up-to-date patches, that is sufficient confirmation to me that this has been fixed.

Will let people know from a Horde support perspective that they need to either downgrade for now or
wait for the next point release.

------------------------------------------------------------------------
[2014-09-23 05:28:26] rdlowrey@php.net

@slusarz Thanks for your offer to help. It's nothing specific you guys are doing at Horde --
it's a problem with the encrypted stream code in ext/openssl. These issues were mostly fixed
before the releases but due to a miscommunication the relevant commits failed to make it into the
5.4.33 and 5.5.17.

I'm quite sorry these issues made it into release as it has also caused plenty of headaches for
me! Some people are quite rude about these sorts of things and don't seem to realize that
pretty much everyone who works on php-src does so as an unpaid volunteer (myself included). I
definitely appreciate your offer to help. I'll be in touch to let you know as soon as this is
fully resolved and/or to ask you guys to do a quick build from source to verify for sure that your
problems are addressed.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=41631


--
Edit this bug report at https://bugs.php.net/bug.php?id=41631&edit=1


Thread (67 messages)

« previous php.bugs (#187723) next »