Req #81704 [Com]: opcache.restrict_api not working with PHP-FPM

From: Date: Tue, 03 Jan 2023 09:56:40 +0000
Subject: Req #81704 [Com]: opcache.restrict_api not working with PHP-FPM
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243317@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81704&edit=1 ID: 81704 Comment by: marlynrasavong at gmail dot com Reported by: mr-manuel at outlook dot it Summary: opcache.restrict_api not working with PHP-FPM Status: Assigned Type: Feature/Change Request Package: opcache Operating System: Debian 11 PHP Version: Irrelevant Assigned To: bukka Block user comment: N Private report: N New Comment: need more information in given words not easy to understand for me. (https://www.nexus-iceland.com/)github.com Previous Comments: ------------------------------------------------------------------------ [2021-12-22 21:58:10] cmb@php.net Thanks for the clarification! I added that info to the PHP manual[1]. [1] <https://github.com/php/doc-en/commit/88333c7e4faf04190cf783247b470c7ea8b54196> ------------------------------------------------------------------------ [2021-12-22 20:44:35] bukka@php.net This is known issue and it's a current design of FPM where MINIT is done on master level and the shared memory is allocated just once. I think the best solution for that would be introducing a process manager that would control pool process and do MINIT but that's quite a lot of work so it will take some time. In any case this is not a security issue because pools are not considered as a security mechanism (read they don't provide full separtion). It is certainly not anything that we can change in the bug fixing release as it will require significant refactoring. This is a feature request though. ------------------------------------------------------------------------ [2021-12-22 13:46:28] cmb@php.net Looks like there is only one OPcache SHM for all FPM pools. Jakub, could you please have a look at this? ------------------------------------------------------------------------ [2021-12-22 09:01:54] mr-manuel at outlook dot it Description: ------------ # actual behaviour OPcache shows all cached files from all PHP-FPM pools using the same PHP version. In addition it shows a negative used_memory value, since it counts somehow all pools and not only the pool in which the script is executed. # expected behaviour OPcache in PHP-FPM should show only the scripts cached within the same pool. # stept to reproduce Use Apache with mpm_event module and PHP-FPM installation. Create per domain a separate PHP-FPM pool and execute the pools with different users. Relevant pool settings: # /etc/php/7.4/fpm/pool.d/domain-1.conf php_admin_flag[opcache.enable] = 1 php_admin_value[opcache.memory_consumption] = 128 php_admin_value[opcache.interned_strings_buffer] = 8 php_admin_value[opcache.max_accelerated_files] = 16229 php_admin_flag[opcache.validate_timestamps] = 1 php_admin_flag[opcache.save_comments] = 1 php_admin_value[opcache.revalidate_freq] = 1 php_admin_flag[opcache.fast_shutdown] = 1 php_admin_value[opcache.restrict_api] = "/var/www/html/domain-1.com" ... rest is default The settings for all domains are the same, except the domain path and config file name. Execute the test script below on every pool/domain and check the scripts. You should see all scripts from all pools which are cached from the same PHP-FPM version. Apache: 2.4.51 PHP versions used: 7.4.26, 8.0.13, 8.1.0 Test script: --------------- https://github.com/rlerdorf/opcache-status/blob/master/opcache.php Expected result: ---------------- OPcache in PHP-FPM should show only the scripts cached within the same pool. Actual result: -------------- OPcache in PHP-FPM shows all scripts that are cached within the same PHP-FPM version. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81704&edit=1

« previous php.bugs (#243317) next »