Doc #52952 [Opn->Asn]: fsockopen() has more dependencies than listed

From: Date: Wed, 13 Oct 2010 09:37:04 +0000
Subject: Doc #52952 [Opn->Asn]: fsockopen() has more dependencies than listed
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-5199@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=52952&edit=1 ID: 52952 Updated by: aharvey@php.net Reported by: victor dot yap at alumni dot concordia dot ca Summary: fsockopen() has more dependencies than listed -Status: Open +Status: Assigned Type: Documentation Problem -Package: Sockets related +Package: Documentation problem Operating System: Linux PHP Version: Irrelevant -Assigned To: +Assigned To: aharvey Block user comment: N New Comment: In terms of the error message, PHP is pretty much repeating whatever OpenSSL gives it, unfortunately. As for the documentation, I'm not terribly keen to start including a list of extra OpenSSL dependencies in each place where the manual says that something works if SSL support is enabled. What I'll do instead is update the OpenSSL installation chapter to include a note about the /dev/*random dependency and update the fsockopen() page (and any others with the same sort of construct) to change the wording of "compiled in" to imply that OpenSSL support also has to be working, beyond simply being included in the binary. Previous Comments: ------------------------------------------------------------------------ [2010-09-29 16:22:21] victor dot yap at alumni dot concordia dot ca Description: ------------ The manual entry for fsockopen() claims this overly simple dependency: "If you have compiled in OpenSSL support, you may prefix the hostname with either ssl:// or tls:// to use an SSL or TLS client connection over TCP/IP to connect to the remote host." However, it will be worth adding a note to point out that "/dev/urandom" is also required, especially setting up chroot'd environments. From what I've dug up briefly, any "/dev/*random" is also acceptable. The error messages given by fsockopen() could also be improved. We experienced a 2 hour development blockage trying to assert that "OpenSSL support" was in fact compiled in... when the root of our problems was simply needing to provide a "/dev/urandom" within the chroot environment. Test script: --------------- // As demonstrated in https://cms.paypal.com/cms_content/US/en_US/files/developer/IPN_PHP_41.txt (retrieved 2010-09-29) $fp = fsockopen ('ssl://www.paypal.com', 443, $errno, $errstr, 30); Expected result: ---------------- While a "/dev/urandom" was our missing link, I'd hope that the documentation will be more thorough and clarify any other potential dependencies that are getting chained along by virtue of OpenSSL. Maybe something along the lines of "In addition to compiled-in support of OpenSSL, your operating environment also needs to support OpenSSL (for example: on *nix systems, ensuring that '/dev/*random' is available for producing random numbers)." The error/warning/notice message that fsockopen() prints out should try to be more clear about why the "ssl://" protocol was not available, mostly to cover this case: - Was there a failure to leverage OpenSSL, even if compiled support is available? The message should then clarify "OpenSSL support has been compiled-in, but cannot be invoked...[because?]" If possible, give even more information: "/dev/*random is unavailable" Actual result: -------------- Without /dev/urandom functioning in our chroot'd environment, fsockopen() prints out some less-than-helpful message about the transport protocol not being available, even though "compiled-in" support was there. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/bug.php?id=52952&edit=1

« previous php.doc.bugs (#5199) next »