Bug #74688 [Com]: SSL stream errors are not exposed by error_get_last()
| From: | larrybrenda665 at gmail dot com | Date: | Mon, 28 Feb 2022 08:51:44 +0000 |
| Subject: | Bug #74688 [Com]: SSL stream errors are not exposed by error_get_last() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-240076@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74688&edit=1
ID: 74688
Comment by: larrybrenda665 at gmail dot com
Reported by: bilge at scriptfusion dot com
Summary: SSL stream errors are not exposed by
error_get_last()
Status: Verified
Type: Bug
Package: HTTP related
Operating System: Linux 2.6.32-642.6.2.el6.x86_64
PHP Version: 5.6.30
Block user comment: N
Private report: N
New Comment:
Outback Steakhouse Happy Hour: In Outbackâs Bloominâ Onion and its spicy signature Bloom
sauce is out. Of. This. World, tasty! Although this isnât available at Happy Hour, itâs
worth noting, as it is a source of joy for me.
https://happy-hours-menu.info/outback-steakhouse-happy-hour/
Previous Comments:
------------------------------------------------------------------------
[2021-01-14 12:52:19] bilge at scriptfusion dot com
What is the resolution, then? Does it get fixed targeting 9.0, or do we add
openssl_transport_error_string()? Both seem like pretty poor solutions to me.
------------------------------------------------------------------------
[2021-01-14 12:47:21] cmb@php.net
Confirmed for PHP 7.4 and 8.0.
The culprit is that SSL transports report errors directly, instead
of logging them to the stream wrapper error queue. I don't think
that can be changed in stable versions for BC reasons, though.
openssl_error_string() is irrelevant for these errors, since SSL
transport errors are not supposed to be reported by that function
anyway.
------------------------------------------------------------------------
[2021-01-13 21:03:25] bilge at scriptfusion dot com
Probably.
------------------------------------------------------------------------
[2021-01-13 18:32:13] cmb@php.net
Is this still an issue with any of the actively supported PHP
versions[1]?
[1] <https://www.php.net/supported-versions.php>
------------------------------------------------------------------------
[2017-06-01 11:54:10] bilge at scriptfusion dot com
Description:
------------
Using file_get_contents() in an object oriented application can be perilous since it emits errors
and warnings directly. We would prefer to silence the call, check the return value and if it's
false retrieve the error message. e.g. if (false === @file_get_contents(...)) { $error =
error_get_last(); }.
This strategy works well for HTTP calls but when one throws SSL into the mix the errors returned by
error_get_last() are different from the ones emitted directly by file_get_contents(). More
specifically, the errors become vague and unhelpful. The real details of the failure can only be
seen by removing the silence operator (@) and thus this is the crux of the bug: it is not possible
to see SSL errors in an object oriented environment.
N.B. Calling openssl_error_string() just returns false.
---
For example, the test script below outputs a general failure message such as:
"file_get_contents(https://[::1]:6666): failed to open stream: Connection refused"
However, since we are using a self-signed certificate, removing the silence operator yields a much
more useful error message from OpenSSL:
file_get_contents(): SSL operation failed with code 1. OpenSSL Error messages:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
The problem is PHP provides no way to capture this output from OpenSSL.
Test script:
---------------
if (false === $response = @file_get_contents(
'https://[::1]:6666',
false,
stream_context_create([
'http' => ['ignore_errors' => true],
])
)) {
echo error_get_last()['message']; // file_get_contents(https://[::1]:6666): failed to
open stream: Connection refused
var_dump(openssl_error_string()); // bool(false)
// We can't see the real error that occurred in the OpenSSL subsystem.
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74688&edit=1