Bug #73342 [Ver]: Vulnerability in php-fpm by changing stdin to non-blocking

From: Date: Mon, 11 Jun 2018 13:06:57 +0000
Subject: Bug #73342 [Ver]: Vulnerability in php-fpm by changing stdin to non-blocking
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215620@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73342&edit=1 ID: 73342 Updated by: nikic@php.net Reported by: xuavis at gmail dot com Summary: Vulnerability in php-fpm by changing stdin to non-blocking Status: Verified Type: Bug Package: FPM related Operating System: Ubuntu 16.04 PHP Version: 7.0Git-2016-10-18 (Git) Assigned To: bukka Block user comment: N Private report: N New Comment: @bukka: What's the ETA on getting this merged? I saw that you submitted the PR for the fpm test revamp, so I assume that we'll start landing outstanding fpm patches soon? Previous Comments: ------------------------------------------------------------------------ [2018-06-11 12:39:23] alex at sirensclef dot com I'm under some pressure to put together a production PHP 7.2 + FPM setup, but then I ran head first into this bug. I don't know what's worse... that a critical subset of PHP functionality is incompatible with PHP-FPM, or that this has been known for so long and nothing has been done. Is anyone aware of a workaround (other than this patch being evaluated)? I've got more of a mod_php background so I'm only just developing an understanding of the options here, but I've had no luck making adjustments to neutralize the issue. I've tested an option, for a dev server, that uses a cron to check the php-fpm log every minute and restart the service whenever the issue arises, but I can't put that into production. Worried this setup is simply a non-starter. ------------------------------------------------------------------------ [2018-04-24 06:10:05] gksalil at gmail dot com Hello Is the patch working and fix the issue ? Can I apply this patch safely ? Thanks ~S ------------------------------------------------------------------------ [2018-03-07 09:22:28] kenny at kennynet dot co dot uk We've deployed the suggested patch removing the use of STDIN internally (currently in testing pending production deployment). I'll update this bug report if we see any problems caused by it. ------------------------------------------------------------------------ [2018-02-25 19:21:00] bukka@php.net @nikic I think that the reason why FPM cares about STDIN is to conform FastCGI spec - namely section 2.2 ( http://www.mit.edu/~yandros/doc/specs/fcgi-spec.html#S2.2 ) that states "FCGI_LISTENSOCK_FILENO equals STDIN_FILENO". I guess it's because maybe some FastCGI application could access the data directly from the record but not really sure why. I can't really see the reason for that in the PHP case. I don't see any side effects of the patch at the moment but it might need a bit more thinking and testing. ------------------------------------------------------------------------ [2018-02-23 21:10:52] nikic@php.net Related To: Bug #67796 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73342 -- Edit this bug report at https://bugs.php.net/bug.php?id=73342&edit=1

« previous php.bugs (#215620) next »