Doc #52952 [Opn->Asn]: fsockopen() has more dependencies than listed
| From: | aharvey@php.net | Date: | Wed, 13 Oct 2010 09:37:04 +0000 |
| Subject: | Doc #52952 [Opn->Asn]: fsockopen() has more dependencies than listed | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-5199@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=52952&edit=1
ID: 52952
Updated by: aharvey@php.net
Reported by: victor dot yap at alumni dot concordia dot ca
Summary: fsockopen() has more dependencies than listed
-Status: Open
+Status: Assigned
Type: Documentation Problem
-Package: Sockets related
+Package: Documentation problem
Operating System: Linux
PHP Version: Irrelevant
-Assigned To:
+Assigned To: aharvey
Block user comment: N
New Comment:
In terms of the error message, PHP is pretty much repeating whatever
OpenSSL gives it, unfortunately.
As for the documentation, I'm not terribly keen to start including a
list of extra OpenSSL dependencies in each place where the manual says
that something works if SSL support is enabled. What I'll do instead is
update the OpenSSL installation chapter to include a note about the
/dev/*random dependency and update the fsockopen() page (and any others
with the same sort of construct) to change the wording of "compiled in"
to imply that OpenSSL support also has to be working, beyond simply
being included in the binary.
Previous Comments:
------------------------------------------------------------------------
[2010-09-29 16:22:21] victor dot yap at alumni dot concordia dot ca
Description:
------------
The manual entry for fsockopen() claims this overly simple dependency:
"If you have compiled in OpenSSL support, you may prefix the hostname
with either ssl:// or tls:// to use an SSL or TLS client connection
over TCP/IP to connect to the remote host."
However, it will be worth adding a note to point out that "/dev/urandom"
is also required, especially setting up chroot'd environments. From
what I've dug up briefly, any "/dev/*random" is also acceptable.
The error messages given by fsockopen() could also be improved.
We experienced a 2 hour development blockage trying to assert that
"OpenSSL support" was in fact compiled in... when the root of our
problems was simply needing to provide a "/dev/urandom" within the
chroot environment.
Test script:
---------------
// As demonstrated in
https://cms.paypal.com/cms_content/US/en_US/files/developer/IPN_PHP_41.txt
(retrieved 2010-09-29)
$fp = fsockopen ('ssl://www.paypal.com', 443, $errno, $errstr, 30);
Expected result:
----------------
While a "/dev/urandom" was our missing link, I'd hope that the
documentation will be more thorough and clarify any other potential
dependencies that are getting chained along by virtue of OpenSSL.
Maybe something along the lines of "In addition to compiled-in support
of OpenSSL, your operating environment also needs to support OpenSSL
(for example: on *nix systems, ensuring that '/dev/*random' is available
for producing random numbers)."
The error/warning/notice message that fsockopen() prints out should try
to be more clear about why the "ssl://" protocol was not available,
mostly to cover this case:
- Was there a failure to leverage OpenSSL, even if compiled support is
available? The message should then clarify "OpenSSL support has been
compiled-in, but cannot be invoked...[because?]"
If possible, give even more information:
"/dev/*random is unavailable"
Actual result:
--------------
Without /dev/urandom functioning in our chroot'd environment,
fsockopen() prints out some less-than-helpful message about the
transport protocol not being available, even though "compiled-in"
support was there.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=52952&edit=1