Req #69090 [Com]: add prefix/xor to cache keys/check permissions or separate caches

From: Date: Fri, 16 Dec 2016 04:01:30 +0000
Subject: Req #69090 [Com]: add prefix/xor to cache keys/check permissions or separate caches
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206049@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69090&edit=1

 ID:                 69090
 Comment by:         me at anatoli dot ws
 Reported by:        simon at ikanobori dot jp
 Summary:            add prefix/xor to cache keys/check permissions or
                     separate caches
 Status:             Closed
 Type:               Feature/Change Request
 Package:            opcache
 Operating System:   linux/debian
 PHP Version:        5.6.5
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N

 New Comment:

The issue in question appears to be fixed, thanks Dmitry for resolving this 2yo security and
stability problem. Nevertheless, IMO the current solution looks more like a workaround for a larger
problem: there's complex code (for which multiple bugs are fixed in half of the releases) that
runs outside the chroot environment with complete visibility of the entire filesystem, making it a
perfect escape route (which was actually demonstrated with the current bug).

IMO, the appropriate fix would be to initialize everything that could access the filesystem
(including internal functionality & all plug-ins) AFTER performing chroot. Only the logic
responsible for loading of the configs, libraries and modules should be placed in the pre-chroot
portion of the daemon (to avoid placing their files in the chroot environment), but NOT their
parsing (for the per-pool configs), initialization (for the modules) and management, which should be
performed in the isolated chrooted environments, a separate instance for each chrooted pool.

If the current logic is to save some memory that could be shared between the chrooted pools, I do
believe that security should not be sacrificed for performance or lower resource usage, especially
nowadays with so cheap hardware.

PHP devs, please let me know if it's appropriate to open a new bug (type: security) for
tracking this change or if this one should be reopened, or if you consider this issue has no merit
to expect its implementation some day.


Previous Comments:
------------------------------------------------------------------------
[2016-11-22 13:14:10] krakjoe@php.net

Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ecba563f2fa1e027ea91b9ee0d50611273852995
Log: Fixed bug #69090 (check cached files permissions)

------------------------------------------------------------------------
[2016-11-16 09:59:39] dmitry@php.net

Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ecba563f2fa1e027ea91b9ee0d50611273852995
Log: Fixed bug #69090 (check cached files permissions)

------------------------------------------------------------------------
[2016-11-16 09:58:45] dmitry@php.net

Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ecba563f2fa1e027ea91b9ee0d50611273852995
Log: Fixed bug #69090 (check cached files permissions)

------------------------------------------------------------------------
[2016-11-15 15:37:58] dmitry@php.net

The following patch has been added/updated:

Patch Name: bug69090.diff
Revision:   1479224278
URL:        https://bugs.php.net/patch-display.php?bug=69090&patch=bug69090.diff&revision=1479224278

------------------------------------------------------------------------
[2016-11-15 15:15:45] dmitry@php.net

The new attached patch should completely fix both problems.

https://bugs.php.net/patch-display.php?bug_id=69090&patch=bug69090.diff&revision=latest

It modifies values of hash function XOR-ing them with a value constructed from the root inode
number. This value calculated once per request, using stat("/") at request startup, if
opcache.validate_root is enabled (disabled by default).

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69090


--
Edit this bug report at https://bugs.php.net/bug.php?id=69090&edit=1


Thread (38 messages)

« previous php.bugs (#206049) next »