Skip to content

Server warns about opcache not running and spams log because opcache API is restricted #3602

Description

@TDannhauer

Steps to reproduce

  1. Install Nextcloud on PHP-FPM 7.0.15
  2. Enable Opcache
  3. Restrict Opcache API to some non-nextcloud files

Expected behaviour

Nextcloud should honor that Opcache API is restricted by security reasons

Actual behaviour

A) Log is spammed with: 'Zend OPcache API is restricted by "restrict_api" configuration directive at //lib/private/legacy/util.php#1349' and 'Zend OPcache API is restricted by "restrict_api" configuration directive at //lib/private/legacy/util.php#1317'
B) Administration page -> Serversettings -> Security warnings states that this server has no opcache running - this is wrong.

Server configuration

Operating system:
Debian Stretch

Web server:
Apache 2.4.25

Database:
Postgres 9.6

PHP version:
7.0.15

Nextcloud version: (see Nextcloud admin page)
11.0.1

Updated from an older Nextcloud/ownCloud or fresh install:
Fresh & pristine install, default settings

Where did you install Nextcloud from:
Server package downloaded from nextcloud.com

Activity

  1. nickvergessen commented on Feb 24, 2017

    @nickvergessen
    Member

    Code in question:

    			// Zend OpCache >= 7.0.0, PHP >= 5.5.0
    			if (function_exists('opcache_invalidate')) {
    				$ret = opcache_invalidate($path);
    			}

    I guess the wrong admin warning is because the results can not be gathered because the methods are restricted as well.

  2. nickvergessen commented on Feb 24, 2017

    @nickvergessen
    Member

    @MorrisJobke a simple config to mute this? Or should we really try to work around this.

    @TDannhauer can you tell how you restricted it?

  3. TDannhauer commented on Feb 24, 2017

    @TDannhauer
    ContributorAuthor
  4. TDannhauer commented on Feb 24, 2017

    @TDannhauer
    ContributorAuthor
  5. MorrisJobke commented on Feb 24, 2017

    @MorrisJobke
    Member

    We do this because when we write to the config.php we need to propagate this to the opcache in use. Maybe we can simply mute the warning with an @, @nickvergessen ?

  6. TDannhauer commented on Feb 25, 2017

    @TDannhauer
    ContributorAuthor
  7. nickvergessen commented on Mar 1, 2017

    @nickvergessen
    Member

    @TDannhauer did you have time to look into it already?

  8. TDannhauer commented on Mar 1, 2017

    @TDannhauer
    ContributorAuthor

    sorry for the delay.

    Yes I looked into it. The problem is to determine whether the function opcache_invalidate() is callable.

    The currently used function_exists() checks only for existence. Unfortuntely, even is_callable() ignores the restricted API.
    It seems PHP does not provide any valid procedure the verify wether the opcache api is usable without throwing any error.

    Therfore the only way to find out whether opcache API is usable is be checking the configuration for "opcache.restrict_api" and compare it to the current script name.

    Since I'm not an PHP expert, I currently struggle to get my configuration value of opcache.restrict_api.

    • ini_get() does not return the correct value
    • get_cfg_var() does not return the correct value

    The only way to figure this out was ini_get_all():

    if (strpos(ini_get_all()['opcache.restrict_api']['global_value'], $_SERVER['SCRIPT_FILENAME']) !== false) echo 'Allowed to use opcache API'; else echo 'NOT allowed to used opcache API';

    What do you think about this approach ?
    // Zend OpCache >= 7.0.0, PHP >= 5.5.0 if (function_exists('opcache_invalidate') && strpos(ini_get_all()['opcache.restrict_api']['global_value'], $_SERVER['SCRIPT_FILENAME']) !== false) $ret = opcache_invalidate($path); }

    Sorry again for beeing not an experienced PHP programmer, C++ is my castle ;)

  9. poVoq commented on Jun 29, 2017

    @poVoq

    Any update on this? My shared host (OVH) also restricts this.

  10. arnowelzel commented on Feb 5, 2018

    @arnowelzel
    Contributor

    The problem still exists with NextCloud 12.0.5.

    Why not just putting @ in front of it to avoid error messages as it is done with apc_delete_file(), apc_clear_cache() etc. as well? If the function can't be called due to restrictions, it makes no sense to get those errors in the logs and if you want to handle the error you should have to check the result anyway:

    			// Zend OpCache >= 7.0.0, PHP >= 5.5.0
    			if (function_exists('opcache_invalidate')) {
    				$ret = @opcache_invalidate($path);
    			}
    

    and there is another location too, where this should be applied:

    		// Opcache (PHP >= 5.5)
    		if (function_exists('opcache_reset')) {
    			@opcache_reset();
    		}
    
  11. nextcloud-bot commented on Jul 5, 2018

    @nextcloud-bot
    Member

    Hey, this issue has been closed because the label stale is set and there were no updates for 14 days. Feel free to reopen this issue if you deem it appropriate.

    (This is an automated comment from GitMate.io.)

  12. MorrisJobke commented on Jul 20, 2018

    @MorrisJobke
    Member

    Fixed by #8188

  13. added this to the Nextcloud 14 milestone on Jul 20, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions