Bug #73412 [Nab]: url-wrappers in PHP7 terrible slow

From: Date: Mon, 31 Oct 2016 08:03:39 +0000
Subject: Bug #73412 [Nab]: url-wrappers in PHP7 terrible slow
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205095@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73412&edit=1

 ID:                 73412
 Updated by:         rasmus@php.net
 Reported by:        spam2 at rhsoft dot net
 Summary:            url-wrappers in PHP7 terrible slow
 Status:             Not a bug
 Type:               Bug
 Package:            Performance problem
 Operating System:   Linux
 PHP Version:        7.0.12
 Block user comment: N
 Private report:     N

 New Comment:

I think a perf report would be more useful, but if you do an strace, use these flags: strace -Ff -tt
-T -o out.txt php -r "get_headers('http://corecms/static.htm');"


Previous Comments:
------------------------------------------------------------------------
[2016-10-31 07:44:34] nikic@php.net

Could you please provide an strace trace for what happens in the get_headers() case?

------------------------------------------------------------------------
[2016-10-31 07:35:44] spam2 at rhsoft dot net

same behavior with your code (replaced the URL and changed 1000 to 20 because otherwise i would need
to wait until next week)

[harry@srv-rhsoft:/downloads]$ php test.php
0.081186056137085
3.1035280227661

the same when it's running within the webserver

interesting that the profiling script used between "make prof-gen" and "make
prof-use" is also doing a ton of file_get_contents on a temporary started webserver on
127.0.0.1:9000 does not suffer from this problem (not within the build-process and also not with the
fallback using the installed binaries) while i have serveral scripts using file_get_contents() or
get_headers() which got magnitudes slower

one of them lists all files recursive and does blind requests to any possible URL to find includes
which are not proper protected against direct calls and that one would take months to finish while
with curl it's pretty fast

------------------------------------------------------------------------
[2016-10-31 06:33:07] rasmus@php.net

I ran the test on mod_php which is using libphp7.so which is compiled with PIC. PIC is the shared
library equivalent of PIE.

But yes, as a matter of fact my cli php is position-independent as well:

11:28pm thinkpad:~/php-src> sapi/cli/php -v
PHP 7.0.14-dev (cli) (built: Oct 27 2016 21:27:10) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
    with Zend OPcache v7.0.13-dev, Copyright (c) 1999-2016, by Zend Technologies

11:28pm thinkpad:~/php-src> hardening-check sapi/cli/php
sapi/cli/php:
 Position Independent Executable: yes
 Stack protected: yes
 Stack protected: yes
 Fortify Source functions: yes
 Read-only relocations: yes
 Immediate binding: yes

11:29pm thinkpad:~/php-src> sapi/cli/php /var/www/html/rr.php
4.9895119667053
5.8754270076752

And as you can see, from the cli the difference is still small. Did you actually run my script?

------------------------------------------------------------------------
[2016-10-31 06:20:59] spam2 at rhsoft dot net

how can you assume http://www.hardened-php.net/ when i
lead you to https://fedoraproject.org/wiki/Changes/Harden_All_Packages
and /usr/bin/hardening-check and talking about PROPER?

is your php cli binary *really* PIE which is *not* the same like PIC

[root@srv-rhsoft:~]$ dnf info hardening-check
Letzte Prüfung auf abgelaufene Metadaten: vor 7:11:06 am Mon Oct 31 00:09:04 2016.
Installierte Pakete
Name        : hardening-check
Arch        : noarch
Epoch       : 0
Version     : 2.5
Release     : 4.fc24
Größe       : 37 k
Paketquelle : @System
Zusammenfas : Tool to check ELF for being built hardened
URL         : http://packages.debian.org/source/sid/hardening-wrapper
Lizenz      : GPLv2+
Beschreibun : hardening-check is a tool to check whether an already compiled ELF file
            : was built using hardening flags.
            :
            : It checks, using readelf, for these hardening characteristics:
            :
            :   * Position Independent Executable
            :   * Stack protected
            :   * Fortify source functions
            :   * Read-only relocations
            :   * Immediate binding

------------------------------------------------------------------------
[2016-10-31 06:04:38] rasmus@php.net

I assumed you meant http://www.hardened-php.net/
My build is using PIC and doesn't show any performance issues.
Do some work to figure out what is going on yourself. With such a drastic difference it should be
obvious in a "perf record" profile.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=73412


--
Edit this bug report at https://bugs.php.net/bug.php?id=73412&edit=1


Thread (19 messages)

« previous php.bugs (#205095) next »