[PATCH] opcache bug #69090, prepend user identifier to keys

From: Date: Fri, 04 Nov 2016 11:00:03 +0000
Subject: [PATCH] opcache bug #69090, prepend user identifier to keys
Groups: php.internals 
Request: Send a blank email to internals+get-96730@lists.php.net to get a copy of this message
Hello, I'm CCing Dmitry Stogov as maintainer because he's listed as an author in ext/opcache/ZendAccelerator.c and has recent commits. I've attached a patch for bug #69090. You can find a more detailed writeup at https://bugs.php.net/bug.php?id=69090 . In short, the patch adds EUID or Windows username at the beginning of OPCache keys to prevent cross-user cache access, which will hopefully alleviate security concerns of enabling OPCache on shared hosting servers. I took this in a different direction than that proposed in bug #69090 (prepending inode to key) because I feel it more effectively addresses the cross-user security concerns. I don't have a test script yet because the change is transparent to scripts, but I could probably cobble one together by checking OPCache debug log for key names. I do intend to port this forward to PHP7 head, but in my opinion the existing behavior in 5.6 is a serious vulnerability which warrants a maintenance patch. If needed I can provide working exploit scripts to demonstrate how bad the existing behavior is for shared servers using OPCache. I was hoping to get some feedback before I put in the effort to port this to PHP7. Thanks, -- - php-dev@coydogsoftware.net

Attachment: [text/x-diff] patch.txt
« previous php.internals (#96730) next »