Bug #73342 [Ver]: Vulnerability in php-fpm by changing stdin to non-blocking

From: Date: Fri, 23 Feb 2018 20:41:44 +0000
Subject: Bug #73342 [Ver]: Vulnerability in php-fpm by changing stdin to non-blocking
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214091@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73342&edit=1

 ID:                 73342
 Updated by:         nikic@php.net
 Reported by:        xuavis at gmail dot com
 Summary:            Vulnerability in php-fpm by changing stdin to
                     non-blocking
 Status:             Verified
 Type:               Bug
 Package:            FPM related
 Operating System:   Ubuntu 16.04
 PHP Version:        7.0Git-2016-10-18 (Git)
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

I think the patch from the first comment only works around the problem ... the real question is
this: Why does FPM care about STDIN at all?

After some looking around, this seems to be what happens:
 * wp->listening_socket is what we actually want to listen on.
 * fpm_globals.listening_socket is always 0 (effectively STDIN), because that's what the global
is initialized to. It's never changed.
 * fpm_run() always returns fpm_globals.listening_socket and that's what fcgi listens on.
 * to make things line up fpm_stdio_init_child() does a dup2(wp->listening_socket, STDIN_FILENO).

So effectively we take the listening socket, dup2 it to STDIN and then listen on STDIN. The
following patch removes the indirection through STDIN:

diff --git a/sapi/fpm/fpm/fpm_children.c b/sapi/fpm/fpm/fpm_children.c
index b48fa54..4ee316b 100644
--- a/sapi/fpm/fpm/fpm_children.c
+++ b/sapi/fpm/fpm/fpm_children.c
@@ -146,6 +146,7 @@ static struct fpm_child_s *fpm_child_find(pid_t pid) /* {{{ */
 static void fpm_child_init(struct fpm_worker_pool_s *wp) /* {{{ */
 {
 	fpm_globals.max_requests = wp->config->pm_max_requests;
+	fpm_globals.listening_socket = dup(wp->listening_socket);
 
 	if (0 > fpm_stdio_init_child(wp)  ||
 	    0 > fpm_log_init_child(wp)    ||
diff --git a/sapi/fpm/fpm/fpm_stdio.c b/sapi/fpm/fpm/fpm_stdio.c
index 4072017..76e8b32 100644
--- a/sapi/fpm/fpm/fpm_stdio.c
+++ b/sapi/fpm/fpm/fpm_stdio.c
@@ -103,12 +103,6 @@ int fpm_stdio_init_child(struct fpm_worker_pool_s *wp) /* {{{ */
 	fpm_globals.error_log_fd = -1;
 	zlog_set_fd(-1);
 
-	if (wp->listening_socket != STDIN_FILENO) {
-		if (0 > dup2(wp->listening_socket, STDIN_FILENO)) {
-			zlog(ZLOG_SYSERROR, "failed to init child stdio: dup2()");
-			return -1;
-		}
-	}
 	return 0;
 }
 /* }}} */

This also resolves the issue for me. However, I don't know if this has any side-effects,
because something else relies on the STDIN mapping.


Previous Comments:
------------------------------------------------------------------------
[2018-02-23 16:55:15] nikic@php.net

Related To: Bug #70185

------------------------------------------------------------------------
[2018-02-23 16:54:23] nikic@php.net

Related To: Bug #75968

------------------------------------------------------------------------
[2018-02-23 16:54:23] nikic@php.net

Related To: Bug #75968

------------------------------------------------------------------------
[2017-07-16 17:15:17] matt at datacodesolutions dot com

This bug is causing issues on our server (Centos 7 / WHM / PHP 70) as well - high load which in turn
cause extremely slow performance.  We use shell_exec to generate PDFs and it seems like this is
causing the PHP-FPM service to get stuck in an endless loop of trying to start and then exiting.

https://serverfault.com/questions/839135/nginx-php-fpm-child-exited-with-code-0

[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62666 exited with code 0 after 0.103145
seconds from start
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62675 started
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62665 exited with code 0 after 0.108670
seconds from start
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62676 started
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62667 exited with code 0 after 0.111453
seconds from start
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62677 started
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62668 exited with code 0 after 0.112478
seconds from start
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62678 started
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62669 exited with code 0 after 0.098957
seconds from start
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62679 started
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62671 exited with code 0 after 0.094954
seconds from start
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62680 started
[16-Jul-2017 12:49:45] NOTICE: [pool mysite_com] child 62670 exited with code 0 after 0.101192
seconds from start

------------------------------------------------------------------------
[2017-05-16 09:05:09] yago dot riveiro at gmail dot com

This bug with Centos 7.0 and php 7 can be reproduced too

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=73342


--
Edit this bug report at https://bugs.php.net/bug.php?id=73342&edit=1


Thread (1 message)

  • nikic@php.net
  • Unknown Message
    • nikic@php.net
« previous php.bugs (#214091) next »