Bug #73929 [NEW]: SSL client socket errors under load with SSL_CTX_new:null ssl method passed in

From: Date: Sat, 14 Jan 2017 00:19:57 +0000
Subject: Bug #73929 [NEW]: SSL client socket errors under load with SSL_CTX_new:null ssl method passed in
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206607@lists.php.net to get a copy of this message
From: tonyp at valvesoftware dot com Operating system: Ubuntu 16.04 PHP version: 7.0.14 Package: Sockets related Bug Type: Bug Bug description:SSL client socket errors under load with SSL_CTX_new:null ssl method passed in Description: ------------ Almost every hit to our web server makes a socket request to another server. Under load, when using PHP 7, we get errors like the following: [Fri Jan 13 15:27:28.692030 2017] [proxy_fcgi:error] [pid 2362] [client <redacted>:60929] AH01071: Got error 'PHP message: PHP Warning: fread(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:140A90C4:SSL routines:SSL_CTX_new:null ssl method passed in <redacted> [Fri Jan 13 15:27:28.751464 2017] [proxy_fcgi:error] [pid 1960] [client <redacted>:61262] AH01071: Got error 'PHP message: PHP Warning: fread(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:140A90C4:SSL routines:SSL_CTX_new:null ssl method passed in <redacted> [Fri Jan 13 15:27:29.404802 2017] [proxy_fcgi:error] [pid 2362] [client <redacted>:60929] AH01071: Got error 'PHP message: PHP Warning: fread(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:140A90C4:SSL routines:SSL_CTX_new:null ssl method passed in <redacted> [Fri Jan 13 15:27:29.487308 2017] [proxy_fcgi:error] [pid 2346] [client <redacted>:63548] AH01071: Got error 'PHP message: PHP Warning: fread(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:140A90C4:SSL routines:SSL_CTX_new:null ssl method passed in <redacted> [Fri Jan 13 15:27:29.668853 2017] [proxy_fcgi:error] [pid 2420] [client <redacted>:42796] AH01071: Got error 'PHP message: PHP Warning: fread(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:140A90C4:SSL routines:SSL_CTX_new:null ssl method passed in <redacted> I have verified that it's actually a socket resource being passed into fread. We do not get these errors in PHP 5. We do not get errors when using non-SSL sockets. Using persistent sockets seems to make the errors occur more frequently, but the problem still occurs when not using persistent sockets. We do use non-SSL persistent sockets elsewhere for things like connections to memcache (Memcache::pconnect). I have tried PHP as an Apache module, and I have tried PHP-FPM. The problem occurs in both. Unfortunately, I have not been able to come up with a reliable repro test script. I have got the error to occur in a script that spins up 1,000 forks and has each fork connect and send data back and forth using SSL sockets, but it's very unreliable. I'm not sure what's happening in production to make the error happen more frequently. The sockets are created using stream_socket_client with the STREAM_CLIENT_CONNECT flag. We create a context using stream_context_create and set allow_self_signed to true. verify_peer and verify_peer_name are set to false. I have not been able to verify whether or not the errors occur without passing or context, or whether or not they occur using fsockopen. The errors occur if even if a specific cipher is specified, or at least occur with the ciphers I've tried (ECDHE-RSA-AES256-GCM-SHA384 for example). The errors occur using ssl://, tls://, and tlsv1.2:// transports. The errors still occur when adding a random identifier after the ip:port combo, for example: 'tls://10.1.2.3:1234/' . rand(0,999999). The code that's failing is an fread call immediately after an fwrite. The fwrite call returns a positive value as it should, and the fread call fails immediately. I have not verified whether or not the data sent by the fwrite call preceding the failing fread call is actually received by the server. Let me know if there's something I can try that will give you more information about the nature of the problem. Test script: --------------- $context = stream_context_create(); stream_context_set_option( $context, 'ssl', 'allow_self_signed', true ); stream_context_set_option( $context, 'ssl', 'verify_peer', false ); stream_context_set_option( $context, 'ssl', 'verify_peer_name', false ); $this->m_pfSocket = stream_socket_client( 'tlsv1.2://' . $ip . ':' . $port, $errno, $errstr, 1.0, STREAM_CLIENT_CONNECT, $context ); -- Edit bug report at https://bugs.php.net/bug.php?id=73929&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73929&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73929&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73929&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=73929&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=73929&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=73929&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=73929&r=needscript Try newer version: https://bugs.php.net/fix.php?id=73929&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=73929&r=support Expected behavior: https://bugs.php.net/fix.php?id=73929&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=73929&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=73929&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=73929&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73929&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=73929&r=dst IIS Stability: https://bugs.php.net/fix.php?id=73929&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=73929&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=73929&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=73929&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=73929&r=mysqlcfg

« previous php.bugs (#206607) next »