Req #69090 [Ana->Csd]: add prefix/xor to cache keys/check permissions or separate caches

From: Date: Wed, 16 Nov 2016 09:58:50 +0000
Subject: Req #69090 [Ana->Csd]: add prefix/xor to cache keys/check permissions or separate caches
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205400@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69090&edit=1

 ID:                 69090
 Updated by:         dmitry@php.net
 Reported by:        simon at ikanobori dot jp
 Summary:            add prefix/xor to cache keys/check permissions or
                     separate caches
-Status:             Analyzed
+Status:             Closed
 Type:               Feature/Change Request
 Package:            opcache
 Operating System:   linux/debian
 PHP Version:        5.6.5
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ecba563f2fa1e027ea91b9ee0d50611273852995
Log: Fixed bug #69090 (check cached files permissions)


Previous Comments:
------------------------------------------------------------------------
[2016-11-15 15:37:58] dmitry@php.net

The following patch has been added/updated:

Patch Name: bug69090.diff
Revision:   1479224278
URL:        https://bugs.php.net/patch-display.php?bug=69090&patch=bug69090.diff&revision=1479224278

------------------------------------------------------------------------
[2016-11-15 15:15:45] dmitry@php.net

The new attached patch should completely fix both problems.

https://bugs.php.net/patch-display.php?bug_id=69090&patch=bug69090.diff&revision=latest

It modifies values of hash function XOR-ing them with a value constructed from the root inode
number. This value calculated once per request, using stat("/") at request startup, if
opcache.validate_root is enabled (disabled by default).

------------------------------------------------------------------------
[2016-11-15 15:11:07] dmitry@php.net

The following patch has been added/updated:

Patch Name: bug69090.diff
Revision:   1479222667
URL:        https://bugs.php.net/patch-display.php?bug=69090&patch=bug69090.diff&revision=1479222667

------------------------------------------------------------------------
[2016-11-15 11:36:18] dmitry@php.net

I've attached a patch to enable optional file permission validation. 

https://bugs.php.net/patch-display.php?bug_id=69090&patch=validate_permission.diff&revision=latest

With opcache.validate_permission=1 php.ini directive, PHP is going to revalidate readability of
cached files using access() syscall. This directive is going to be disabled by default and should be
enabled by shared hosting providers. Additional checks lead to ~5% slowdown on Wordpress.

The proposed manipulations with keys (e.g. including user name or root directory into key)
won't work out of the box, because in some cases opcache doesn't use keys constructed by
accel_make_persistent_key(), but uses full-real-name instead.

I didn't solve the chroot keys collision problem yet.

------------------------------------------------------------------------
[2016-11-15 11:21:20] dmitry@php.net

The following patch has been added/updated:

Patch Name: validate_permission.diff
Revision:   1479208880
URL:        https://bugs.php.net/patch-display.php?bug=69090&patch=validate_permission.diff&revision=1479208880

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69090


--
Edit this bug report at https://bugs.php.net/bug.php?id=69090&edit=1


Thread (38 messages)

« previous php.bugs (#205400) next »