Bug #78889 [Csd]: php-fpm service fails to start

From: Date: Sun, 01 Dec 2019 17:29:37 +0000
Subject: Bug #78889 [Csd]: php-fpm service fails to start
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223989@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78889&edit=1 ID: 78889 Updated by: bukka@php.net Reported by: glitsj16 at riseup dot net Summary: php-fpm service fails to start Status: Closed Type: Bug Package: FPM related Operating System: Arch Linux PHP Version: 7.4.0 Assigned To: bukka Block user comment: N Private report: N New Comment: So I identified potentially another missing capability for chroot and not really sure if there are more. So I removed CapabilityBoundingSet completely for PHP 7.4. I created a PR that could re-introduce it in master with all capabilities needed: https://github.com/php/php-src/pull/4960 . If you can think of any, please add a comment. In addition I removed MemoryDenyWriteExecute as I agree with Nikita that this could break PCRE JIT. Previous Comments: ------------------------------------------------------------------------ [2019-12-01 17:17:37] bukka@php.net Automatic comment on behalf of bukka Revision: http://git.php.net/?p=php-src.git;a=commit;h=67cd4271e922ee3082b416a7563598274d13a1e5 Log: Fix bug #78889 (php-fpm service fails to start) ------------------------------------------------------------------------ [2019-12-01 17:13:27] bukka@php.net Automatic comment on behalf of bukka Revision: http://git.php.net/?p=php-src.git;a=commit;h=67cd4271e922ee3082b416a7563598274d13a1e5 Log: Fix bug #78889 (php-fpm service fails to start) ------------------------------------------------------------------------ [2019-12-01 13:07:12] nikic@php.net For reference, this was added in https://github.com/php/php-src/commit/40c4d7f1820df1872a71ab07fd26da45a203e37f. Adding CAP_CHOWN sounds reasonable. What also jumps out to me is that this enables MemoryDenyWriteExecute, which seems like a very bad idea, as it should break PCRE JIT. Unless I misunderstand what this file applies to. ------------------------------------------------------------------------ [2019-12-01 12:14:01] fgfgfgfg at somewhere dot com > that is, in your opinion, the administrator of the > web server, in addition to the configuration files, > must also configure the systemd-unit file itself, > if it changes something in the configuration file? surely that's what /etc/systemd/systemd/servicename.service.d/ dropins are for or in case of the distribution /usr/lib/systemd/system/servicename.service.d/ if you change or add something you are supposed to know what you are doing ------------------------------------------------------------------------ [2019-12-01 09:18:44] ilya at ilya dot pp dot ua FPM is part of PHP. systemd-unit file is shipped in the PHP tarball. They decided to add a CapabilityBoundingSet to it, but they didn’t add it completely, they forgot to add CAP_CHOWN. Why do you think this is not a PHP bug? That is, in your opinion, the administrator of the web server, in addition to the configuration files, must also configure the systemd-unit file itself, if it changes something in the configuration file? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78889 -- Edit this bug report at https://bugs.php.net/bug.php?id=78889&edit=1

« previous php.bugs (#223989) next »