aboutsummaryrefslogtreecommitdiffhomepage
path: root/docs
diff options
context:
space:
mode:
authornsfisis <nsfisis@gmail.com>2026-08-06 20:50:24 +0900
committernsfisis <nsfisis@gmail.com>2026-08-06 20:50:24 +0900
commit14a8a474120ef4289625f05ba5d87fa9e9d19542 (patch)
treee4d810bda2808a5624b313846331b4888facee1f /docs
parent91e7102d02cfcda0bf1b82ae1b3fb30900495360 (diff)
downloadphp-shirabe-14a8a474120ef4289625f05ba5d87fa9e9d19542.tar.gz
php-shirabe-14a8a474120ef4289625f05ba5d87fa9e9d19542.tar.zst
php-shirabe-14a8a474120ef4289625f05ba5d87fa9e9d19542.zip
fix(php-rpc): carry the worker channel over a socketpair
The transport bound an AF_UNIX path under TMPDIR and waited for the child to connect. That path has to fit in sun_path (108 bytes), so a deep TMPDIR made every worker spawn fail, and the bind(2) itself is denied under a sandbox. The parent now keeps one end of a socketpair and installs the other on descriptor 3 before exec, which the worker opens as php://fd/3. The pair is connected from the start, so the accept poll and its ten-second deadline are gone; a child that dies before reading surfaces as EOF on the first call, where worker_state already attaches its exit status. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Diffstat (limited to 'docs')
-rw-r--r--docs/dev/php-rpc.md13
1 files changed, 9 insertions, 4 deletions
diff --git a/docs/dev/php-rpc.md b/docs/dev/php-rpc.md
index e55f860e..77d0d365 100644
--- a/docs/dev/php-rpc.md
+++ b/docs/dev/php-rpc.md
@@ -17,11 +17,16 @@ behavior.
## Transport
-- A Unix domain socket (no Windows support for now), bound in a `0700` temp dir with the socket
- file itself chmodded to `0600`.
+- A `socketpair(2)` (no Windows support for now). The parent keeps one end and installs the
+ other on descriptor 3 in the child, from a `pre_exec` hook, so the worker opens it as
+ `php://fd/3` rather than connecting anywhere. A bound path would have to fit in `sun_path`
+ (108 bytes), which a long `TMPDIR` overruns, and it needs a `bind(2)` that sandboxes commonly
+ deny. The pair is connected from the start, so nothing has to wait for an `accept` either: a
+ child that dies before reading surfaces as EOF on the first call, with its exit status
+ attached.
- The PHP glue code (`php/worker.php`) and the proxy stub classes (`php/stubs/`) are embedded in
- the Rust binary and written to the temp dir at spawn time, so both halves of the protocol are
- always the same commit.
+ the Rust binary and written to a `0700` temp dir at spawn time, so both halves of the protocol
+ are always the same commit.
### Frame layout