Bug #73412 [Nab]: url-wrappers in PHP7 terrible slow
| From: | rasmus@php.net | Date: | Mon, 31 Oct 2016 06:33:12 +0000 |
| Subject: | Bug #73412 [Nab]: url-wrappers in PHP7 terrible slow | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205091@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73412&edit=1
ID: 73412
Updated by: rasmus@php.net
Reported by: spam2 at rhsoft dot net
Summary: url-wrappers in PHP7 terrible slow
Status: Not a bug
Type: Bug
Package: Performance problem
Operating System: Linux
PHP Version: 7.0.12
Block user comment: N
Private report: N
New Comment:
I ran the test on mod_php which is using libphp7.so which is compiled with PIC. PIC is the shared
library equivalent of PIE.
But yes, as a matter of fact my cli php is position-independent as well:
11:28pm thinkpad:~/php-src> sapi/cli/php -v
PHP 7.0.14-dev (cli) (built: Oct 27 2016 21:27:10) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
with Zend OPcache v7.0.13-dev, Copyright (c) 1999-2016, by Zend Technologies
11:28pm thinkpad:~/php-src> hardening-check sapi/cli/php
sapi/cli/php:
Position Independent Executable: yes
Stack protected: yes
Stack protected: yes
Fortify Source functions: yes
Read-only relocations: yes
Immediate binding: yes
11:29pm thinkpad:~/php-src> sapi/cli/php /var/www/html/rr.php
4.9895119667053
5.8754270076752
And as you can see, from the cli the difference is still small. Did you actually run my script?
Previous Comments:
------------------------------------------------------------------------
[2016-10-31 06:20:59] spam2 at rhsoft dot net
how can you assume http://www.hardened-php.net/ when i
lead you to https://fedoraproject.org/wiki/Changes/Harden_All_Packages
and /usr/bin/hardening-check and talking about PROPER?
is your php cli binary *really* PIE which is *not* the same like PIC
[root@srv-rhsoft:~]$ dnf info hardening-check
Letzte Prüfung auf abgelaufene Metadaten: vor 7:11:06 am Mon Oct 31 00:09:04 2016.
Installierte Pakete
Name : hardening-check
Arch : noarch
Epoch : 0
Version : 2.5
Release : 4.fc24
GröÃe : 37 k
Paketquelle : @System
Zusammenfas : Tool to check ELF for being built hardened
URL : http://packages.debian.org/source/sid/hardening-wrapper
Lizenz : GPLv2+
Beschreibun : hardening-check is a tool to check whether an already compiled ELF file
: was built using hardening flags.
:
: It checks, using readelf, for these hardening characteristics:
:
: * Position Independent Executable
: * Stack protected
: * Fortify source functions
: * Read-only relocations
: * Immediate binding
------------------------------------------------------------------------
[2016-10-31 06:04:38] rasmus@php.net
I assumed you meant http://www.hardened-php.net/
My build is using PIC and doesn't show any performance issues.
Do some work to figure out what is going on yourself. With such a drastic difference it should be
obvious in a "perf record" profile.
------------------------------------------------------------------------
[2016-10-31 06:01:38] spam2 at rhsoft dot net
> No, I test clean PHP binaries. No 3rd-party hacks
when you think position independent executeable is a 3rd party hack why don't you handover the
bugreport to someone who is serious instead close it?
all the PHP5 builds from the last years where PIE builds too without that performance problem
------------------------------------------------------------------------
[2016-10-31 05:47:23] rasmus@php.net
No, I test clean PHP binaries. No 3rd-party hacks. And like I showed with my example, there is no
major performance difference between url wrappers and curl.
------------------------------------------------------------------------
[2016-10-31 05:21:24] spam2 at rhsoft dot net
Hi
thanks for feedback - please dont miss the part under the line - mabye that's the reason
we talk about 0.647s versus 36s for jsut 50 requests here while the libcurl variant takes 29s for
FIVE THOUSAND requests and that's hardly a difference between GET/HEAD (BTW: why in the world
does get_headers() make GET requests while http://php.net/manual/de/function.get-headers.php
don't claim that as also common sense says GET by what it does and the fact that even with
<Limit GET POST> you can't disable HEAD-Requests - point is it feels like doing 1 request
per second which is not far from teh truth and i have a script doing around 100000 requests which
was fine with 5.x and pure file_get_contents()
____________________________________
is your PHP build a proper hardened build?
i saw as example when Fedora 23 switched the whole distribution https://fedoraproject.org/wiki/Changes/Harden_All_Packages
grep go magnitued slower and now with F24 it's as fast as before and still a hardened build, so
i guess there was some bug in the code which made it make that way
[root@srv-rhsoft:~]$ /usr/bin/hardening-check /usr/bin/php
/usr/bin/php:
Position Independent Executable: yes
Stack protected: yes
Fortify Source functions: yes (some protected functions found)
Read-only relocations: yes
Immediate binding: yes
if that's the reason may i suggest developers only test with hardened builds because no one
should run these days any non-PIE/non-FULLRELRO code except broken one which don't build proper
and can't yet replaced
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73412
--
Edit this bug report at https://bugs.php.net/bug.php?id=73412&edit=1