Bug #68751 [Com]: listen.allowed_clients is broken

From: Date: Thu, 08 Jan 2015 18:19:59 +0000
Subject: Bug #68751 [Com]: listen.allowed_clients is broken
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189747@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68751&edit=1 ID: 68751 Comment by: gui@php.net Reported by: remi@php.net Summary: listen.allowed_clients is broken Status: Closed Type: Bug Package: FPM related Operating System: GNU/LInux PHP Version: 5.5.20 Assigned To: remi Block user comment: N Private report: N New Comment: @iquito : I'll try to provide (patched 5.5.20 / 5.5.21 if available) packages in the next few days, so that we can provide feedback to @remi. Previous Comments: ------------------------------------------------------------------------ [2015-01-06 19:56:05] iquito at gmx dot ch Sorry, but I have never done anything like it - that is why I use debian packages, I have never compiled anything myself and only use well-tested repositories. I just wanted to describe the error, because I am a "regular user" of PHP who tries to be cautious with upgrading and configuration because of limited resources and in-depth knowledge, but was still stuck with this problem and it had a catastrophic effect on my web servers. That is why I have already tested for hours to somehow "isolate" what happens and make an accurate description, so somebody more experienced and familiar with PHP can find and understand the problem behind it. ------------------------------------------------------------------------ [2015-01-06 18:49:39] remi@php.net @iquito: so please, test the fix. ------------------------------------------------------------------------ [2015-01-06 18:39:11] iquito at gmx dot ch I have a problem with PHP-FPM which seems to be connected to this bug. The detailed version is on https://github.com/gplessis/dotdeb-php5/issues/69 , the short of it is: When multiple addresses are listed in listen.allowed_clients for just one FPM pool config, FPM terminates any further connections from any IP addresses of any pool after one request to any of the pools (as far as I can tell). Only if all pools only have one IP address in listen.allowed_clients FPM seems to work normally again. This has lead to a complete FPM failure on all of my servers without a hint of where the problem occured, except it is somehow related to FPM, as CLI still worked. In my opinion, PHP 5.5.20 should not be further distributed as long as this bug is contained in it, as existing configurations are likely to break - multiple IPs in listen.allowed_clients seem a common configuration choice, and mitigating this problem is not straightforward. ------------------------------------------------------------------------ [2015-01-06 10:21:14] igor dot ajdisek at gmail dot com I can confirm this now works. I no longer see any 'Connection disallowed' errors and all requests succeed. ------------------------------------------------------------------------ [2015-01-06 10:08:01] remi@php.net @samo: you're right. Cleanup: http://git.php.net/?p=php-src.git;a=commitdiff;h=8404f8ac2a540780422d9813138a9c6785405312 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68751 -- Edit this bug report at https://bugs.php.net/bug.php?id=68751&edit=1

« previous php.bugs (#189747) next »