Edit report at https://bugs.php.net/bug.php?id=69090&edit=1
ID: 69090
Comment by: me at anatoli dot ws
Reported by: simon at ikanobori dot jp
Summary: add prefix/xor to cache keys/check permissions or
separate caches
Status: Closed
Type: Feature/Change Request
Package: opcache
Operating System: linux/debian
PHP Version: 5.6.5
Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
The issue in question appears to be fixed, thanks Dmitry for resolving this 2yo security and
stability problem. Nevertheless, IMO the current solution looks more like a workaround for a larger
problem: there's complex code (for which multiple bugs are fixed in half of the releases) that
runs outside the chroot environment with complete visibility of the entire filesystem, making it a
perfect escape route (which was actually demonstrated with the current bug).
IMO, the appropriate fix would be to initialize everything that could access the filesystem
(including internal functionality & all plug-ins) AFTER performing chroot. Only the logic
responsible for loading of the configs, libraries and modules should be placed in the pre-chroot
portion of the daemon (to avoid placing their files in the chroot environment), but NOT their
parsing (for the per-pool configs), initialization (for the modules) and management, which should be
performed in the isolated chrooted environments, a separate instance for each chrooted pool.
If the current logic is to save some memory that could be shared between the chrooted pools, I do
believe that security should not be sacrificed for performance or lower resource usage, especially
nowadays with so cheap hardware.
PHP devs, please let me know if it's appropriate to open a new bug (type: security) for
tracking this change or if this one should be reopened, or if you consider this issue has no merit
to expect its implementation some day.
Previous Comments:
------------------------------------------------------------------------
[2016-11-22 13:14:10] krakjoe@php.net
Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ecba563f2fa1e027ea91b9ee0d50611273852995
Log: Fixed bug #69090 (check cached files permissions)
------------------------------------------------------------------------
[2016-11-16 09:59:39] dmitry@php.net
Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ecba563f2fa1e027ea91b9ee0d50611273852995
Log: Fixed bug #69090 (check cached files permissions)
------------------------------------------------------------------------
[2016-11-16 09:58:45] dmitry@php.net
Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ecba563f2fa1e027ea91b9ee0d50611273852995
Log: Fixed bug #69090 (check cached files permissions)
------------------------------------------------------------------------
[2016-11-15 15:37:58] dmitry@php.net
The following patch has been added/updated:
Patch Name: bug69090.diff
Revision: 1479224278
URL: https://bugs.php.net/patch-display.php?bug=69090&patch=bug69090.diff&revision=1479224278
------------------------------------------------------------------------
[2016-11-15 15:15:45] dmitry@php.net
The new attached patch should completely fix both problems.
https://bugs.php.net/patch-display.php?bug_id=69090&patch=bug69090.diff&revision=latest
It modifies values of hash function XOR-ing them with a value constructed from the root inode
number. This value calculated once per request, using stat("/") at request startup, if
opcache.validate_root is enabled (disabled by default).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69090
--
Edit this bug report at https://bugs.php.net/bug.php?id=69090&edit=1