Bug #74429 [Csd]: Remote socket URI with unique persistence identifier broken

From: Date: Fri, 28 Apr 2017 17:50:54 +0000
Subject: Bug #74429 [Csd]: Remote socket URI with unique persistence identifier broken
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208847@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74429&edit=1 ID: 74429 Updated by: pollita@php.net Reported by: martijn dot grendelman at isaac dot nl Summary: Remote socket URI with unique persistence identifier broken Status: Closed Type: Bug Package: Streams related Operating System: Any PHP Version: 7.0.18RC1 Assigned To: pollita Block user comment: N Private report: N New Comment: I need to sit down later and collate all the myriad places bad transport strings get created (both intentionally and unintentionally) and I'll start a thread on internals to that effect. I'll be happy to cc you at the time to make sure you see it. :D Previous Comments: ------------------------------------------------------------------------ [2017-04-28 09:43:57] dominic at varspool dot com Thanks for the patch ab! Further discussion of the future of this undocumented hack (as it has rightly been called), and any possible replacement (maybe a stream context option?) will, I presume, take place on the mailing list? I'd recommend nuking the user note at http://php.net/manual/en/function.stream-socket-client.php#105393 to limit the spread of the problem, in any case, though. ------------------------------------------------------------------------ [2017-04-25 12:11:32] ab@php.net The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. ------------------------------------------------------------------------ [2017-04-21 13:19:11] requinix@php.net Related To: Bug #74486 ------------------------------------------------------------------------ [2017-04-18 21:40:44] pollita@php.net For what it's worth, https://gist.github.com/sgolemon/51f329655a94523546f081bf9c9afd31 is probably safe enough to use as it would still cover the security case given by bug #74216, it would allow colinmollenhour's hack to keep working, and it's fairly "URI-ish", so it's not an unreasonable looking thing. I'm not personally convinced though. ------------------------------------------------------------------------ [2017-04-18 21:16:29] pollita@php.net No. That "undocumented feature" was never intended to work, and the use of it is an abuse of the API. As to allowing multiple persistent connections to a backend resource, I think we could add official support for it via a new API, and perhaps even matching this use case, but it's going to take some discussion because I don't want to trivially walk into codifying something for no better reason that "It worked on accident at some point." ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=74429 -- Edit this bug report at https://bugs.php.net/bug.php?id=74429&edit=1

« previous php.bugs (#208847) next »