Bug #69574 [Com]: ldap timeouts not enforced

From: Date: Wed, 09 Sep 2015 15:24:23 +0000
Subject: Bug #69574 [Com]: ldap timeouts not enforced
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195916@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69574&edit=1

 ID:                 69574
 Comment by:         mcmic@php.net
 Reported by:        ryan dot brothers at gmail dot com
 Summary:            ldap timeouts not enforced
 Status:             Assigned
 Type:               Bug
 Package:            LDAP related
 Operating System:   Linux
 PHP Version:        5.6.8
 Assigned To:        mcmic
 Block user comment: N
 Private report:     N

 New Comment:

Ok, so the problem is:

LDAP_OPT_TIMELIMIT is only for searches, not bind operations
LDAP_OPT_NETWORK_TIMEOUT is for socket level timeout, in your test there is no such thing as the nc
is indeed listening on the socket.

What you need is LDAP_OPT_TIMEOUT from openldap, which is not available yet in PHP.
So I’m gonna add this to php-ldap as it seems usefull.


Previous Comments:
------------------------------------------------------------------------
[2015-09-09 13:51:38] mcmic@php.net

Ok, got it, I had to do «nc -l -p 1234» instead of «nc -l 1234».
I can reproduce the bug.

------------------------------------------------------------------------
[2015-09-09 13:48:41] mcmic@php.net

I meant I replaced it by «$ldap = ldap_connect('localhost', 1234);», sorry.

------------------------------------------------------------------------
[2015-09-09 13:47:47] mcmic@php.net

I can’t reproduce this, I tried your script, I got «PHP Warning:  ldap_connect(): Could not
create session handle: Bad parameter to an ldap routine in /tmp/test.php on line 3»
So I replaced the call to ldap_connect by «$ldap = ldap_connect('127.0.0.1:1234');»
I launched «nc -l 1234» in a shell, in an other one the PHP script, I only got «PHP
Warning:  ldap_bind(): Unable to bind to server: Can't contact LDAP server in /tmp/test.php on
line 8» immediatly, not even after 3 seconds.

Not sure how to test this otherwise…

------------------------------------------------------------------------
[2015-05-05 13:54:06] ryan dot brothers at gmail dot com

Description:
------------
I am trying to simulate a LDAP server timing out.  I'm setting the options
LDAP_OPT_NETWORK_TIMEOUT and LDAP_OPT_TIMELIMIT, but the script runs indefinitely without timing
out.

In one ssh session, I am running the following command to simulate a socket listener:

nc -l 1234

If I run the below script in a second ssh session, it runs forever and never times out.

Is there a way to have this script timeout after a certain number of seconds?


Test script:
---------------
<?php
$ldap = ldap_connect('127.0.0.1:1234');

ldap_set_option($ldap, LDAP_OPT_NETWORK_TIMEOUT, 3);
ldap_set_option($ldap, LDAP_OPT_TIMELIMIT, 3);

ldap_bind($ldap);


Expected result:
----------------
Script times out in 3 seconds.


Actual result:
--------------
Script never times out.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69574&edit=1


Thread (12 messages)

« previous php.bugs (#195916) next »