Bug #67244 [Csd]: Wrong owner:group for listening unix socket

From: Date: Fri, 13 Jan 2023 10:35:16 +0000
Subject: Bug #67244 [Csd]: Wrong owner:group for listening unix socket
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243434@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67244&edit=1 ID: 67244 Updated by: bukka@php.net Reported by: bugs-php at antipoul dot fr Summary: Wrong owner:group for listening unix socket Status: Closed Type: Bug Package: FPM related Operating System: Linux PHP Version: 5.5.12 -Assigned To: +Assigned To: bukka Block user comment: N Private report: N New Comment: Thanks for the report and apology for taking so long to fix it. I have updated the comments so hopefully it all makes more sense now. Previous Comments: ------------------------------------------------------------------------ [2023-01-13 10:34:00] git@php.net Automatic comment on behalf of bukka Revision: https://github.com/php/php-src/commit/120aafcc42c0d24f17b61dec98efb91bba86483b Log: Fix bug #67244: Wrong owner:group for listening unix socket ------------------------------------------------------------------------ [2019-08-28 12:19:06] bernard+php at rosset dot net The misleading comment is still there, more than 5 years later. Reviewing old configurations I thought those listen.owner & listen.group directives were extraneous... which they were not. Any hope to have those directives' comment fixed anytime soon? ------------------------------------------------------------------------ [2014-05-30 15:10:28] carl dot george at rackspace dot com I agree that the comment is misleading. Please clarify this in all versions, not just 5.6. ------------------------------------------------------------------------ [2014-05-12 09:25:30] bugs-php at antipoul dot fr In the commented file packaged by Debian, the default chmod is correct (0660). But the other comment, regarding the owner of the unix socket is plainly wrong. It could be modified, but I liked the idea where it just copies the settings from user/group. If the worker from FPM is run with a particular user/group, then the socket should belong to it… ------------------------------------------------------------------------ [2014-05-11 23:12:59] peter dot mescalchin at gmail dot com Yeah this is somewhat related to my ticket https://bugs.php.net/bug.php?id=67175 basically the permissions for the socket have changed from 0666 to 0660 as of 5.5.12. What I think has been happening in your case: - The socket was always being created as root:root - Since the socket WAS 0666 any process could hook into it (e.g. Nginx) - Now that's no longer the case. Also the comments around "Default Values: user and group are set as the running user" is a little confusing - it's NOT the user that the php-fpm childs will run as (user=/group=) but the user that starts the php-fpm daemon - which if from upstart/init.d/systemd will typically be root (and a good choice). In your final example it's working as expected - the default group for the www-data user is www-data so it's using that. There is zero interaction between (user=/group=) and (listen.owner=/listen.group=) settings. In the end this all boils down to improvements in both PHP documentation and comments in php-fpm.conf. I have submitted a change to the PHP docs (to say that default is 0660 - not committed yet) - php-fpm.conf has some changes coming for PHP 5.6, but maybe this confusion you have here could be better explained. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=67244 -- Edit this bug report at https://bugs.php.net/bug.php?id=67244&edit=1

« previous php.bugs (#243434) next »