Bug #73929 [NEW]: SSL client socket errors under load with SSL_CTX_new:null ssl method passed in
| From: | tonyp at valvesoftware dot com | Date: | Sat, 14 Jan 2017 00:19:57 +0000 |
| Subject: | Bug #73929 [NEW]: SSL client socket errors under load with SSL_CTX_new:null ssl method passed in | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-206607@lists.php.net to get a copy of this message | ||
From: tonyp at valvesoftware dot com
Operating system: Ubuntu 16.04
PHP version: 7.0.14
Package: Sockets related
Bug Type: Bug
Bug description:SSL client socket errors under load with SSL_CTX_new:null ssl method passed in
Description:
------------
Almost every hit to our web server makes a socket request to another
server. Under load, when using PHP 7, we get errors like the following:
[Fri Jan 13 15:27:28.692030 2017] [proxy_fcgi:error] [pid 2362] [client
<redacted>:60929] AH01071: Got error 'PHP message: PHP Warning:
fread(): SSL operation failed with code 1. OpenSSL Error
messages:\nerror:140A90C4:SSL routines:SSL_CTX_new:null ssl method
passed in <redacted>
[Fri Jan 13 15:27:28.751464 2017] [proxy_fcgi:error] [pid 1960] [client
<redacted>:61262] AH01071: Got error 'PHP message: PHP Warning:
fread(): SSL operation failed with code 1. OpenSSL Error
messages:\nerror:140A90C4:SSL routines:SSL_CTX_new:null ssl method
passed in <redacted>
[Fri Jan 13 15:27:29.404802 2017] [proxy_fcgi:error] [pid 2362] [client
<redacted>:60929] AH01071: Got error 'PHP message: PHP Warning:
fread(): SSL operation failed with code 1. OpenSSL Error
messages:\nerror:140A90C4:SSL routines:SSL_CTX_new:null ssl method
passed in <redacted>
[Fri Jan 13 15:27:29.487308 2017] [proxy_fcgi:error] [pid 2346] [client
<redacted>:63548] AH01071: Got error 'PHP message: PHP Warning:
fread(): SSL operation failed with code 1. OpenSSL Error
messages:\nerror:140A90C4:SSL routines:SSL_CTX_new:null ssl method
passed in <redacted>
[Fri Jan 13 15:27:29.668853 2017] [proxy_fcgi:error] [pid 2420] [client
<redacted>:42796] AH01071: Got error 'PHP message: PHP Warning:
fread(): SSL operation failed with code 1. OpenSSL Error
messages:\nerror:140A90C4:SSL routines:SSL_CTX_new:null ssl method
passed in <redacted>
I have verified that it's actually a socket resource being passed into
fread.
We do not get these errors in PHP 5. We do not get errors when using
non-SSL sockets. Using persistent sockets seems to make the errors occur
more frequently, but the problem still occurs when not using persistent
sockets. We do use non-SSL persistent sockets elsewhere for things like
connections to memcache (Memcache::pconnect).
I have tried PHP as an Apache module, and I have tried PHP-FPM. The
problem occurs in both.
Unfortunately, I have not been able to come up with a reliable repro
test script. I have got the error to occur in a script that spins up
1,000 forks and has each fork connect and send data back and forth using
SSL sockets, but it's very unreliable. I'm not sure what's happening in
production to make the error happen more frequently.
The sockets are created using stream_socket_client with the
STREAM_CLIENT_CONNECT flag. We create a context using
stream_context_create and set allow_self_signed to true. verify_peer and
verify_peer_name are set to false. I have not been able to verify
whether or not the errors occur without passing or context, or whether
or not they occur using fsockopen. The errors occur if even if a
specific cipher is specified, or at least occur with the ciphers I've
tried (ECDHE-RSA-AES256-GCM-SHA384 for example).
The errors occur using ssl://, tls://, and tlsv1.2:// transports. The
errors still occur when adding a random identifier after the ip:port
combo, for example: 'tls://10.1.2.3:1234/' . rand(0,999999).
The code that's failing is an fread call immediately after an fwrite.
The fwrite call returns a positive value as it should, and the fread
call fails immediately. I have not verified whether or not the data sent
by the fwrite call preceding the failing fread call is actually received
by the server.
Let me know if there's something I can try that will give you more
information about the nature of the problem.
Test script:
---------------
$context = stream_context_create();
stream_context_set_option( $context, 'ssl', 'allow_self_signed', true
);
stream_context_set_option( $context, 'ssl', 'verify_peer', false );
stream_context_set_option( $context, 'ssl', 'verify_peer_name', false
);
$this->m_pfSocket = stream_socket_client( 'tlsv1.2://' . $ip . ':' .
$port, $errno, $errstr, 1.0, STREAM_CLIENT_CONNECT, $context );
--
Edit bug report at https://bugs.php.net/bug.php?id=73929&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73929&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73929&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73929&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73929&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73929&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73929&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73929&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73929&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73929&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73929&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73929&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73929&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73929&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73929&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73929&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73929&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73929&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73929&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73929&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73929&r=mysqlcfg