Bug #78889 [Com]: php-fpm service fails to start

From: Date: Sat, 30 Nov 2019 16:44:25 +0000
Subject: Bug #78889 [Com]: php-fpm service fails to start
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223968@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78889&edit=1

 ID:                 78889
 Comment by:         build+php at de-korte dot org
 Reported by:        glitsj16 at riseup dot net
 Summary:            php-fpm service fails to start
 Status:             Assigned
 Type:               Bug
 Package:            FPM related
 Operating System:   Arch Linux
 PHP Version:        7.4.0
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

I don't want to be picking nits, but in the default configuration, php-fpm will listen to an
AF_INET socket (127.0.0.1:9000), not an AF_UNIX socket (/run/php-fpm/php-fpm.sock) like mentioned in
this report. The reported issue will only occur in the latter case, not in the first (which is the
default).


Previous Comments:
------------------------------------------------------------------------
[2019-11-30 13:39:16] cmb@php.net

Jakub, could you please check this?

------------------------------------------------------------------------
[2019-11-30 13:38:19] cmb@php.net

Related To: Bug #78892

------------------------------------------------------------------------
[2019-11-30 01:21:25] glitsj16 at riseup dot net

During ongoing discussion in https://bugs.archlinux.org/task/64683 it was
suggested to leave the CapabilityBoundingSet as-is, but edit /etc/php/php-fpm.d/www.conf instead.
This looks the cleaner way of fixing this.

https://bugs.archlinux.org/task/64683#comment184101

In /etc/php/php-fpm.d/www.conf replace
;listen.acl_users =
;listen.acl_groups =
with
listen.acl_users = http
listen.acl_groups = http

https://bugs.archlinux.org/task/64683#comment184102

@loqs Enabling ACL in /etc/php/php-fpm.d/www.conf as you suggested works for me. I also commented
;listen.owner = http
;listen.group = http
to avoid
[WARNING] [pool www] ACL set, listen.owner = 'http' is ignored
[WARNING] [pool www] ACL set, listen.group = 'http' is ignored
in systemctl status php-fpm.service

Doing so deprecates the attached patch. It is up to the devs whether or not the needed changes to
www.conf can be left for maintainers to implement or if anything can be done by upstream.

------------------------------------------------------------------------
[2019-11-29 21:30:25] glitsj16 at riseup dot net

Description:
------------
php-fpm.service fails to start after upgrading to php 7.4.0. Using the default configuration files.

systemctl status php-fpm.service:

systemd[1]: Starting The PHP FastCGI Process Manager...
php-fpm[10704]: [ERROR] [pool www] failed to chown() the socket
'/run/php-fpm/php-fpm.sock': Operation not permitted (1)
php-fpm[10704]: [ERROR] [pool www] failed to chown() the socket
'/run/php-fpm/php-fpm.sock': Operation not permitted (1)
php-fpm[10704]: [ERROR] FPM initialization failed
php-fpm[10704]: [ERROR] FPM initialization failed
systemd[1]: php-fpm.service: Main process exited, code=exited, status=78/CONFIG
systemd[1]: php-fpm.service: Failed with result 'exit-code'.
systemd[1]: Failed to start The PHP FastCGI Process Manager.

This has been reported in the Arch bug tracker: https://bugs.archlinux.org/task/64683
Looks like the CapabilityBoundingSet needs to include CAP_CHOWN



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78889&edit=1


Thread (10 messages)

« previous php.bugs (#223968) next »