Repository navigation
Server warns about opcache not running and spams log because opcache API is restricted #3602
Description
Activity
Code in question:
// Zend OpCache >= 7.0.0, PHP >= 5.5.0 if (function_exists('opcache_invalidate')) { $ret = opcache_invalidate($path); }
I guess the wrong admin warning is because the results can not be gathered because the methods are restricted as well.
@MorrisJobke a simple config to mute this? Or should we really try to work around this.
@TDannhauer can you tell how you restricted it?
- Yes thats right. Why tries the code to invalidate the code?
- Sure: In the PHP-FPM pool via php_admin_value[opcache.restrict_api] = /<path to opcache managing PHP scipt> e.g. php_admin_value[opcache.restrict_api] = //var/www/admin/opmonitor.php In my opinion nextcloud should not do anything with the opcache. AFAIK there is no need the disable timestamp revalidation, since it is cached by the kernel und fast to query. At least, the invalidation should only happen if opcache.validate_timestamps is set to off. If it is set to on, there is no need to invalidate.
We do this because when we write to the config.php we need to propagate this to the opcache in use. Maybe we can simply mute the warning with an
@, @nickvergessen ?- This would be very dirty imo. I'll provide a clean patch proposal this evening. Von unterwegs gesendet Sent from mobile…Am 24.02.2017 um 22:40 schrieb Morris Jobke ***@***.***>: We do this because when we write to the config.php we need to propagate this to the opcache in use. Maybe we can simply mute the warning with an @, @nickvergessen ? — You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub, or mute the thread.Reacted by Joas Schilling
@TDannhauer did you have time to look into it already?
sorry for the delay.
Yes I looked into it. The problem is to determine whether the function opcache_invalidate() is callable.
The currently used function_exists() checks only for existence. Unfortuntely, even is_callable() ignores the restricted API.
It seems PHP does not provide any valid procedure the verify wether the opcache api is usable without throwing any error.Therfore the only way to find out whether opcache API is usable is be checking the configuration for "opcache.restrict_api" and compare it to the current script name.
Since I'm not an PHP expert, I currently struggle to get my configuration value of opcache.restrict_api.
- ini_get() does not return the correct value
- get_cfg_var() does not return the correct value
The only way to figure this out was ini_get_all():
if (strpos(ini_get_all()['opcache.restrict_api']['global_value'], $_SERVER['SCRIPT_FILENAME']) !== false) echo 'Allowed to use opcache API'; else echo 'NOT allowed to used opcache API';What do you think about this approach ?
// Zend OpCache >= 7.0.0, PHP >= 5.5.0 if (function_exists('opcache_invalidate') && strpos(ini_get_all()['opcache.restrict_api']['global_value'], $_SERVER['SCRIPT_FILENAME']) !== false) $ret = opcache_invalidate($path); }Sorry again for beeing not an experienced PHP programmer, C++ is my castle ;)
Any update on this? My shared host (OVH) also restricts this.
The problem still exists with NextCloud 12.0.5.
Why not just putting
@in front of it to avoid error messages as it is done withapc_delete_file(),apc_clear_cache()etc. as well? If the function can't be called due to restrictions, it makes no sense to get those errors in the logs and if you want to handle the error you should have to check the result anyway:// Zend OpCache >= 7.0.0, PHP >= 5.5.0 if (function_exists('opcache_invalidate')) { $ret = @opcache_invalidate($path); }and there is another location too, where this should be applied:
// Opcache (PHP >= 5.5) if (function_exists('opcache_reset')) { @opcache_reset(); }- addedstaleTicket or PR with no recent activityTicket or PR with no recent activity
on Jun 20, 2018 Hey, this issue has been closed because the label
staleis set and there were no updates for 14 days. Feel free to reopen this issue if you deem it appropriate.(This is an automated comment from GitMate.io.)
- removedstaleTicket or PR with no recent activityTicket or PR with no recent activity
on Jul 5, 2018 - added and removed
on Jul 5, 2018 Fixed by #8188
Steps to reproduce
Expected behaviour
Nextcloud should honor that Opcache API is restricted by security reasons
Actual behaviour
A) Log is spammed with: 'Zend OPcache API is restricted by "restrict_api" configuration directive at //lib/private/legacy/util.php#1349' and 'Zend OPcache API is restricted by "restrict_api" configuration directive at //lib/private/legacy/util.php#1317'
B) Administration page -> Serversettings -> Security warnings states that this server has no opcache running - this is wrong.
Server configuration
Operating system:
Debian Stretch
Web server:
Apache 2.4.25
Database:
Postgres 9.6
PHP version:
7.0.15
Nextcloud version: (see Nextcloud admin page)
11.0.1
Updated from an older Nextcloud/ownCloud or fresh install:
Fresh & pristine install, default settings
Where did you install Nextcloud from:
Server package downloaded from nextcloud.com