Bug #65137 [Com]: stream_select misleads when TLS socket is used

From: Date: Mon, 22 Dec 2014 14:00:42 +0000
Subject: Bug #65137 [Com]: stream_select misleads when TLS socket is used
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189147@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65137&edit=1

 ID:                 65137
 Comment by:         boen dot robot at gmail dot com
 Reported by:        boen dot robot at gmail dot com
 Summary:            stream_select misleads when TLS socket is used
 Status:             Closed
 Type:               Bug
 Package:            Streams related
 Operating System:   Windows Server 2008 R2
 PHP Version:        5.5.0
 Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

I'd like to point out that this issue is still not resolved, as daverandom's fix was
reverted due to the related issue askalski points to.

(So... the status shouldn't really be "Closed"...)

IMHO, that fix, while POTENTIALLY bad for performance (in SOME cases...), is better than no fix at
all, because encrypted sockets are almost impossible to work with otherwise. When people use an
encrypted connection, they are ready to sacrifice a little performance anyway.

A proper fix, I think, would involve a modification in PHP's stream API, where instead of just
PHP_STREAM_AS_FD_FOR_SELECT, there would be PHP_STREAM_AS_FD_FOR_SELECT_READ,
PHP_STREAM_AS_FD_FOR_SELECT_WRITE and PHP_STREAM_AS_FD_FOR_SELECT_OOB, allowing the OpenSSL
extension (and potentially other streams) to flush the appropriate buffers, as opposed to
"all" buffers, which is what the current fix is doing. The PHP_STREAM_AS_FD_FOR_SELECT
constant could be modified to be a bitmask that OR's all those new ones, thus minimizing
migration problems.


Previous Comments:
------------------------------------------------------------------------
[2014-10-02 17:05:15] askalski at synacor dot com

Related To: Bug #41631

------------------------------------------------------------------------
[2014-08-27 15:51:06] daverandom@php.net

The fix for this bug has been committed.

Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.

 For Windows:

http://windows.php.net/snapshots/
 
Thank you for the report, and for helping us make PHP better.



------------------------------------------------------------------------
[2014-08-23 01:04:37] daverandom@php.net

This occurs because OpenSSL has an internal buffer, which stream_select() does not inspect.

I've just thrown a patch together [1] which fixes the issue for me, I'm going to try and
squeeze it into 5.4.32, not sure if that ship has sailed yet, it may have to be 5.5+ only as
it's not really a security fix in the strictest sense.

[1] https://github.com/DaveRandom/php-src/compare/fix/ssl-stream-select-buffer

------------------------------------------------------------------------
[2014-04-03 14:49:00] boen dot robot at gmail dot com

To ab@php.net:

Sorry for not responding earlier - and no, I'm not using x64 bins. All bins are the x86 NTS
bins from windows.php.net.

------------------------------------------------------------------------
[2014-04-03 14:27:03] heruan at aldu dot net

This is also happening when a stream_socket_server() accepts a connection and
stream_socket_enable_crypto() on it; then, stream_select() reports data on a read socket but an
immediate fread() returns empty, while usleep() a bit before fread() succeeds. This is happening on
Linux with PHP 5.5.9.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=65137


--
Edit this bug report at https://bugs.php.net/bug.php?id=65137&edit=1


Thread (19 messages)

« previous php.bugs (#189147) next »