Bug #67481 [Opn->Csd]: Opcache uses wrong file from cache

From: Date: Thu, 01 Jan 2015 22:11:12 +0000
Subject: Bug #67481 [Opn->Csd]: Opcache uses wrong file from cache
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189586@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67481&edit=1

 ID:                 67481
 User updated by:    Danack at basereality dot com
 Reported by:        Danack at basereality dot com
 Summary:            Opcache uses wrong file from cache
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            opcache
 Operating System:   Centos
 PHP Version:        5.5.13
 Block user comment: N
 Private report:     N

 New Comment:

It turns out this is not a bug, it is the behaviour that is expected when opcache.use_cwd is set to
zero.

With it set to zero OPCache does not include the current path in the name used for the cached
script, and so OPcache cannot tell two scripts with the same name in different directories apart.

The setting opcache.use_cwd should always be enabled unless PHP is going to be running a single
application with known unique file names.


Previous Comments:
------------------------------------------------------------------------
[2014-09-24 22:30:37] public+php dot net at bastelstu dot be

It would be great to be able to specify a prefix for the opcache key. This would easily allow to
separate the caches for different pools.

------------------------------------------------------------------------
[2014-09-10 06:46:09] spam at rw23 dot de

This is also a big security issue for two reasons:
1. it allows to read files from other chroots (containing secrets)
if you know another chroot vhost (project1) is running a wordpress installation, you can create a
file with a path existing on project1 like /web/wp-config.php in project2, include it from project2
and then echo DB_PASSWORD, DB_HOST and so on. you can read the secrets from project1.

2. i have not tried it, but i think it allows to override files on other chroots and inject
arbitrary code.
you can create a /web/index.php containing a php backdoor. if the opcache for that file gets cleared
(server restart, garbage collection) and your file is the first loaded into cache again, you have
your code executed in other chroots.

a user running chroots without overlapping files will not notice this problem, bringing this
vulnerability into production enviroments.

------------------------------------------------------------------------
[2014-09-10 06:19:59] spam at rw23 dot de

php version is 5.5.16 for me

------------------------------------------------------------------------
[2014-09-10 06:16:06] spam at rw23 dot de

its a common problem and also a deal-breaker when using chrooted enviroments like the php-fpm setup,
you can find many complains on the net:
https://www.google.com/search?q=php-fpm+chroot+opcache.so

by using a config file from a wrong neighbor project, this bug can even break things.
this is not happening with APC or xcache, so these work around the problem somehow.

------------------------------------------------------------------------
[2014-08-09 03:59:32] wojjie at gmail dot com

Same problem exists if you are in a chroot environment. Consider the example provided by the
original author and add chroot to the project directories.

ie:

/home/project1/
/home/project2/

Now each site's index.php is actually:

/web/index.php   (project1)
/web/index.php   (project2)


Somehow this also causes a collision in the cache and causes PHP to serve the wrong index.php from
cache if you hit project1 first followed by project2 next.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=67481


--
Edit this bug report at https://bugs.php.net/bug.php?id=67481&edit=1


Thread (19 messages)

« previous php.bugs (#189586) next »