Req #81704 [Com]: opcache.restrict_api not working with PHP-FPM
| From: | marlynrasavong at gmail dot com | Date: | Tue, 03 Jan 2023 09:56:40 +0000 |
| Subject: | Req #81704 [Com]: opcache.restrict_api not working with PHP-FPM | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-243317@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81704&edit=1
ID: 81704
Comment by: marlynrasavong at gmail dot com
Reported by: mr-manuel at outlook dot it
Summary: opcache.restrict_api not working with PHP-FPM
Status: Assigned
Type: Feature/Change Request
Package: opcache
Operating System: Debian 11
PHP Version: Irrelevant
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
need more information in given words not easy to understand for me.
(https://www.nexus-iceland.com/)github.com
Previous Comments:
------------------------------------------------------------------------
[2021-12-22 21:58:10] cmb@php.net
Thanks for the clarification! I added that info to the PHP
manual[1].
[1] <https://github.com/php/doc-en/commit/88333c7e4faf04190cf783247b470c7ea8b54196>
------------------------------------------------------------------------
[2021-12-22 20:44:35] bukka@php.net
This is known issue and it's a current design of FPM where MINIT is done on master level and
the shared memory is allocated just once. I think the best solution for that would be introducing a
process manager that would control pool process and do MINIT but that's quite a lot of work so
it will take some time.
In any case this is not a security issue because pools are not considered as a security mechanism
(read they don't provide full separtion). It is certainly not anything that we can change in
the bug fixing release as it will require significant refactoring. This is a feature request though.
------------------------------------------------------------------------
[2021-12-22 13:46:28] cmb@php.net
Looks like there is only one OPcache SHM for all FPM pools.
Jakub, could you please have a look at this?
------------------------------------------------------------------------
[2021-12-22 09:01:54] mr-manuel at outlook dot it
Description:
------------
# actual behaviour
OPcache shows all cached files from all PHP-FPM pools using the same PHP version. In addition it
shows a negative used_memory value, since it counts somehow all pools and not only the pool in which
the script is executed.
# expected behaviour
OPcache in PHP-FPM should show only the scripts cached within the same pool.
# stept to reproduce
Use Apache with mpm_event module and PHP-FPM installation. Create per domain a separate PHP-FPM pool
and execute the pools with different users.
Relevant pool settings:
# /etc/php/7.4/fpm/pool.d/domain-1.conf
php_admin_flag[opcache.enable] = 1
php_admin_value[opcache.memory_consumption] = 128
php_admin_value[opcache.interned_strings_buffer] = 8
php_admin_value[opcache.max_accelerated_files] = 16229
php_admin_flag[opcache.validate_timestamps] = 1
php_admin_flag[opcache.save_comments] = 1
php_admin_value[opcache.revalidate_freq] = 1
php_admin_flag[opcache.fast_shutdown] = 1
php_admin_value[opcache.restrict_api] = "/var/www/html/domain-1.com"
... rest is default
The settings for all domains are the same, except the domain path and config file name.
Execute the test script below on every pool/domain and check the scripts. You should see all scripts
from all pools which are cached from the same PHP-FPM version.
Apache: 2.4.51
PHP versions used: 7.4.26, 8.0.13, 8.1.0
Test script:
---------------
https://github.com/rlerdorf/opcache-status/blob/master/opcache.php
Expected result:
----------------
OPcache in PHP-FPM should show only the scripts cached within the same pool.
Actual result:
--------------
OPcache in PHP-FPM shows all scripts that are cached within the same PHP-FPM version.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81704&edit=1