Edit report at https://bugs.php.net/bug.php?id=65137&edit=1
ID: 65137
Updated by: requinix@php.net
Reported by: boen dot robot at gmail dot com
Summary: stream_select misleads when TLS socket is used
-Status: Closed
+Status: Re-Opened
Type: Bug
Package: Streams related
Operating System: Windows Server 2008 R2
PHP Version: 5.5.0
-Assigned To: ab
+Assigned To:
Block user comment: N
Private report: N
New Comment:
https://github.com/php/php-src/commit/7b8222aa44bbab9928afd57adb1bc04cf291d46c
Previous Comments:
------------------------------------------------------------------------
[2015-02-09 13:38:58] sjaillet at gmail dot com
Is it possible have the status of this bug updated ? Thanks !
------------------------------------------------------------------------
[2014-12-22 14:00:41] boen dot robot at gmail dot com
I'd like to point out that this issue is still not resolved, as daverandom's fix was
reverted due to the related issue askalski points to.
(So... the status shouldn't really be "Closed"...)
IMHO, that fix, while POTENTIALLY bad for performance (in SOME cases...), is better than no fix at
all, because encrypted sockets are almost impossible to work with otherwise. When people use an
encrypted connection, they are ready to sacrifice a little performance anyway.
A proper fix, I think, would involve a modification in PHP's stream API, where instead of just
PHP_STREAM_AS_FD_FOR_SELECT, there would be PHP_STREAM_AS_FD_FOR_SELECT_READ,
PHP_STREAM_AS_FD_FOR_SELECT_WRITE and PHP_STREAM_AS_FD_FOR_SELECT_OOB, allowing the OpenSSL
extension (and potentially other streams) to flush the appropriate buffers, as opposed to
"all" buffers, which is what the current fix is doing. The PHP_STREAM_AS_FD_FOR_SELECT
constant could be modified to be a bitmask that OR's all those new ones, thus minimizing
migration problems.
------------------------------------------------------------------------
[2014-10-02 17:05:15] askalski at synacor dot com
Related To: Bug #41631
------------------------------------------------------------------------
[2014-08-27 15:51:06] daverandom@php.net
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
------------------------------------------------------------------------
[2014-08-23 01:04:37] daverandom@php.net
This occurs because OpenSSL has an internal buffer, which stream_select() does not inspect.
I've just thrown a patch together [1] which fixes the issue for me, I'm going to try and
squeeze it into 5.4.32, not sure if that ship has sailed yet, it may have to be 5.5+ only as
it's not really a security fix in the strictest sense.
[1] https://github.com/DaveRandom/php-src/compare/fix/ssl-stream-select-buffer
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=65137
--
Edit this bug report at https://bugs.php.net/bug.php?id=65137&edit=1