Bug #74688 [NEW]: SSL stream errors are not exposed by error_get_last()
| From: | bilge at scriptfusion dot com | Date: | Thu, 01 Jun 2017 11:54:12 +0000 |
| Subject: | Bug #74688 [NEW]: SSL stream errors are not exposed by error_get_last() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-209341@lists.php.net to get a copy of this message | ||
From: bilge at scriptfusion dot com
Operating system: Linux 2.6.32-642.6.2.el6.x86_64
PHP version: 5.6.30
Package: HTTP related
Bug Type: Bug
Bug description:SSL stream errors are not exposed by error_get_last()
Description:
------------
Using file_get_contents() in an object oriented application can be
perilous since it emits errors and warnings directly. We would prefer to
silence the call, check the return value and if it's false retrieve the
error message. e.g. if (false === @file_get_contents(...)) { $error =
error_get_last(); }.
This strategy works well for HTTP calls but when one throws SSL into the
mix the errors returned by error_get_last() are different from the ones
emitted directly by file_get_contents(). More specifically, the errors
become vague and unhelpful. The real details of the failure can only be
seen by removing the silence operator (@) and thus this is the crux of
the bug: it is not possible to see SSL errors in an object oriented
environment.
N.B. Calling openssl_error_string() just returns false.
---
For example, the test script below outputs a general failure message
such as:
"file_get_contents(https://[::1]:6666): failed to open stream:
Connection refused"
However, since we are using a self-signed certificate, removing the
silence operator yields a much more useful error message from OpenSSL:
file_get_contents(): SSL operation failed with code 1. OpenSSL Error
messages:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate
verify failed
The problem is PHP provides no way to capture this output from OpenSSL.
Test script:
---------------
if (false === $response = @file_get_contents(
'https://[::1]:6666',
false,
stream_context_create([
'http' => ['ignore_errors' => true],
])
)) {
echo error_get_last()['message']; //
file_get_contents(https://[::1]:6666): failed to open stream: Connection
refused
var_dump(openssl_error_string()); // bool(false)
// We can't see the real error that occurred in the OpenSSL
subsystem.
}
--
Edit bug report at https://bugs.php.net/bug.php?id=74688&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74688&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74688&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74688&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74688&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74688&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74688&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74688&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74688&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74688&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74688&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74688&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74688&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74688&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74688&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74688&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74688&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74688&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74688&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74688&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74688&r=mysqlcfg