Bug #71223 [Opn->Wfx]: Unix socket permissions are not always correct

From: Date: Mon, 09 Jan 2017 05:43:51 +0000
Subject: Bug #71223 [Opn->Wfx]: Unix socket permissions are not always correct
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206423@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71223&edit=1 ID: 71223 Updated by: krakjoe@php.net Reported by: gmoniker at gmail dot com Summary: Unix socket permissions are not always correct -Status: Open +Status: Wont fix Type: Bug Package: FPM related PHP Version: 5.6.16 Block user comment: N Private report: N New Comment: The pull request on github was closed because 5.6 is in security fix only release cycle. Please open a clean PR against a supported branch. Previous Comments: ------------------------------------------------------------------------ [2015-12-26 01:40:43] gmoniker at gmail dot com Pull request made for 5.6.17: Explicitly set the Unix socket permission bits #1697 ------------------------------------------------------------------------ [2015-12-26 01:18:00] gmoniker at gmail dot com Where I say 440 in the bug report it should be 660 obviously. ------------------------------------------------------------------------ [2015-12-26 01:16:26] gmoniker at gmail dot com Description: ------------ The listen.mode setting of a worker pool allows to set the basic Unix permission bits. If you set it to 440 it should have rw-rw---- for example. The way it is set up in fpm_unix.c is to set an inverted umask and then create the socket with that umask. This works on filesystems with only basic permissions. However if you install on a filesystem with Posix ACL, then the default mask for the parent directory may interfere with this, and the socket file gets the wrong permission bits, possibly missing a necessary write permission. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71223&edit=1

« previous php.bugs (#206423) next »