[PATCH] opcache bug #69090, prepend user identifier to keys
| From: | php-dev at coydogsoftware dot net | Date: | Fri, 04 Nov 2016 11:00:03 +0000 |
| Subject: | [PATCH] opcache bug #69090, prepend user identifier to keys | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-96730@lists.php.net to get a copy of this message | ||
Hello,
I'm CCing Dmitry Stogov as maintainer because he's listed as an author in ext/opcache/ZendAccelerator.c and has recent commits.
I've attached a patch for bug #69090. You can find a more detailed writeup at https://bugs.php.net/bug.php?id=69090 . In short, the patch adds EUID or Windows username at the beginning of OPCache keys to prevent cross-user cache access, which will hopefully alleviate security concerns of enabling OPCache on shared hosting servers.
I took this in a different direction than that proposed in bug #69090 (prepending inode to key) because I feel it more effectively addresses the cross-user security concerns.
I don't have a test script yet because the change is transparent to scripts, but I could probably cobble one together by checking OPCache debug log for key names. I do intend to port this forward to PHP7 head, but in my opinion the existing behavior in 5.6 is a serious vulnerability which warrants a maintenance patch. If needed I can provide working exploit scripts to demonstrate how bad the existing behavior is for shared servers using OPCache.
I was hoping to get some feedback before I put in the effort to port this to PHP7.
Thanks,
--
- php-dev@coydogsoftware.net
Attachment: [text/x-diff] patch.txt
Attachment: [text/x-diff] patch.txt