Bug #78889 [Com]: php-fpm service fails to start
| From: | ilya at ilya dot pp dot ua | Date: | Sun, 01 Dec 2019 09:18:44 +0000 |
| Subject: | Bug #78889 [Com]: php-fpm service fails to start | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223980@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78889&edit=1
ID: 78889
Comment by: ilya at ilya dot pp dot ua
Reported by: glitsj16 at riseup dot net
Summary: php-fpm service fails to start
Status: Assigned
Type: Bug
Package: FPM related
Operating System: Arch Linux
PHP Version: 7.4.0
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
FPM is part of PHP.
systemd-unit file is shipped in the PHP tarball.
They decided to add a CapabilityBoundingSet to it, but they didnât add it completely, they
forgot to add CAP_CHOWN.
Why do you think this is not a PHP bug?
That is, in your opinion, the administrator of the web server, in addition to the configuration
files, must also configure the systemd-unit file itself, if it changes something in the
configuration file?
Previous Comments:
------------------------------------------------------------------------
[2019-11-30 17:16:19] glitsj16 at riseup dot net
The bug is inded triggered when using an AF_UNIX socket. That should have been caught by the
downstream Arch maintainer(s) who decided to change the defaults and broke the php-fpm service. This
has been rectified via the 7.4.0-2 release so I think this can be closed. Thanks for looking into
this.
------------------------------------------------------------------------
[2019-11-30 16:44:25] build+php at de-korte dot org
I don't want to be picking nits, but in the default configuration, php-fpm will listen to an
AF_INET socket (127.0.0.1:9000), not an AF_UNIX socket (/run/php-fpm/php-fpm.sock) like mentioned in
this report. The reported issue will only occur in the latter case, not in the first (which is the
default).
------------------------------------------------------------------------
[2019-11-30 13:39:16] cmb@php.net
Jakub, could you please check this?
------------------------------------------------------------------------
[2019-11-30 13:38:19] cmb@php.net
Related To: Bug #78892
------------------------------------------------------------------------
[2019-11-30 01:21:25] glitsj16 at riseup dot net
During ongoing discussion in https://bugs.archlinux.org/task/64683 it was
suggested to leave the CapabilityBoundingSet as-is, but edit /etc/php/php-fpm.d/www.conf instead.
This looks the cleaner way of fixing this.
https://bugs.archlinux.org/task/64683#comment184101
In /etc/php/php-fpm.d/www.conf replace
;listen.acl_users =
;listen.acl_groups =
with
listen.acl_users = http
listen.acl_groups = http
https://bugs.archlinux.org/task/64683#comment184102
@loqs Enabling ACL in /etc/php/php-fpm.d/www.conf as you suggested works for me. I also commented
;listen.owner = http
;listen.group = http
to avoid
[WARNING] [pool www] ACL set, listen.owner = 'http' is ignored
[WARNING] [pool www] ACL set, listen.group = 'http' is ignored
in systemctl status php-fpm.service
Doing so deprecates the attached patch. It is up to the devs whether or not the needed changes to
www.conf can be left for maintainers to implement or if anything can be done by upstream.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78889
--
Edit this bug report at https://bugs.php.net/bug.php?id=78889&edit=1