Bug #41631 [Com]: default_socket_timeout does not work with SSL

From: Date: Sun, 28 Sep 2014 16:21:26 +0000
Subject: Bug #41631 [Com]: default_socket_timeout does not work with SSL
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187737@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=41631&edit=1

 ID:                 41631
 Comment by:         askalski at synacor dot com
 Reported by:        david at acz dot org
 Summary:            default_socket_timeout does not work with SSL
 Status:             Re-Opened
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   *
 PHP Version:        5.2, 5.3, 5.4, 5.5, 5.6
 Assigned To:        rdlowrey
 Block user comment: N
 Private report:     N

 New Comment:

Both versions of the patch (bug41631.patch and ssl_read_timeout-5.4.32.patch) need more rigorous
testing before they can be released.  I'm willing to help devise a set of tests we can use to
validate the implementation.

To illustrate the point without getting to deep into things (it's still the weekend!),
here's a test which fails on bug41631.patch, and gives an endless stream of warnings:

<?php
/* nonblocking-write.php */
$ssl = fsockopen("ssl://localhost", 6767);
stream_set_blocking($ssl, 0);
while (fwrite($ssl, str_repeat("x", 65536)) !== false);
?>

# Window 1
$ sudo tc qdisc add dev lo root netem delay 100ms
$ openssl s_server -cert server.pem -key server.key -accept 6767 >/dev/null
...
$ sudo tc qdisc del dev lo root netem delay 100ms

# Window 2
$ php nonblocking-write.php
Warning: fwrite(): SSL operation failed with code 1. OpenSSL Error messages:
error:1409F07F:SSL routines:SSL3_WRITE_PENDING:bad write retry in
/home/askalski/work/php-bug41631/nonblocking-write.php on line 4


The artificial network delay via the NetEm driver is not required to reproduce the error, but rather
makes it more reliable to reproduce.  Don't forget to remove the delay after you're done
testing.  You can verify it's removed by checking the ping times of "ping localhost".

If you need to generate a self-signed key for testing with "openssl s_server", here's
a quick and dirty way:
$ openssl genrsa -out server.key
$ yes "" | openssl req -new -key server.key -out certreq.csr ; echo
$ openssl x509 -req -days 3650 -in certreq.csr -signkey server.key -out server.pem


Previous Comments:
------------------------------------------------------------------------
[2014-09-26 18:43:06] askalski at synacor dot com

I attached a locally-maintained patch for this bug that we've been running in production for
the past 3 years.  I'm curious to know if this version of the fix works with Horde?

------------------------------------------------------------------------
[2014-09-26 15:37:36] software-php at interfasys dot ch

Even after the patches were applied, Horde could not connect to the sieve server (4190) using TLS,
so something is still very wrong.

------------------------------------------------------------------------
[2014-09-26 14:14:04] admin at brandensittich dot de

This Problem also affects Roundcube Webmail 1.0.2

PHP 5.5.17-1~dotdeb.1 (cli) (built: Sep 19 2014 01:56:56)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies
with Zend OPcache v7.0.4-dev, Copyright (c) 1999-2014, by Zend Technologies


[26-Sep-2014 16:02:55 Europe/Berlin] PHP Warning:  fgets(): SSL read operation timed out in
[...]/program/lib/Roundcube/rcube_imap_generic.php on line 200

    /**
     * Reads line from the connection stream
     *
     * @param int  $size  Buffer size
     *
     * @return string Line of text response
     */
    function readLine($size=1024)
    {
        $line = '';

        if (!$size) {
            $size = 1024;
        }

        do {
            if ($this->eof()) {
                return $line ? $line : NULL;
            }

            // Line 200: SSL read operation timed out
            $buffer = fgets($this->fp, $size);

            if ($buffer === false) {
                $this->closeSocket();
                break;
            }
            if ($this->_debug) {
                $this->debug('S: '. rtrim($buffer));
            }
            $line .= $buffer;
        } while (substr($buffer, -1) != "\n");

        return $line;
    }

------------------------------------------------------------------------
[2014-09-26 08:08:00] stas@php.net

Since 5.4 is now in security-fixes mode, and the patch for this issue that got into 5.4.33 was not
good, I have reverted the 5.4 branch to its 5.4.32 status for xp_ssl.c. Please verify ASAP that this
does not cause additional regressions for 5.4. In 5.5, it still stays as it was before and
additional fixes can be applied there if needed.

------------------------------------------------------------------------
[2014-09-24 06:11:13] slusarz at horde dot org

@rdlowery: Thanks for the update.  Given @software-horde report that things are working with Horde
with the most up-to-date patches, that is sufficient confirmation to me that this has been fixed.

Will let people know from a Horde support perspective that they need to either downgrade for now or
wait for the next point release.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=41631


--
Edit this bug report at https://bugs.php.net/bug.php?id=41631&edit=1


Thread (67 messages)

« previous php.bugs (#187737) next »