From 14a8a474120ef4289625f05ba5d87fa9e9d19542 Mon Sep 17 00:00:00 2001 From: nsfisis Date: Thu, 6 Aug 2026 20:50:24 +0900 Subject: fix(php-rpc): carry the worker channel over a socketpair The transport bound an AF_UNIX path under TMPDIR and waited for the child to connect. That path has to fit in sun_path (108 bytes), so a deep TMPDIR made every worker spawn fail, and the bind(2) itself is denied under a sandbox. The parent now keeps one end of a socketpair and installs the other on descriptor 3 before exec, which the worker opens as php://fd/3. The pair is connected from the start, so the accept poll and its ten-second deadline are gone; a child that dies before reading surfaces as EOF on the first call, where worker_state already attaches its exit status. Co-Authored-By: Claude Opus 5 (1M context) --- crates/shirabe-php-rpc/php/worker.php | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) (limited to 'crates/shirabe-php-rpc/php/worker.php') diff --git a/crates/shirabe-php-rpc/php/worker.php b/crates/shirabe-php-rpc/php/worker.php index e82c45ba..092f535f 100644 --- a/crates/shirabe-php-rpc/php/worker.php +++ b/crates/shirabe-php-rpc/php/worker.php @@ -427,10 +427,14 @@ final class ShirabeRpcRuntime } } -$client = @stream_socket_client('unix://' . $argv[1], $errno, $errstr); +// The socket is one end of a socketpair the parent installed on this descriptor before exec; +// there is nothing to connect to. See docs/dev/php-rpc.md. +$client = @fopen('php://fd/' . $argv[1], 'r+b'); if ($client === false) { exit(1); } +// Frames must reach the parent as they are written, not when a buffer happens to fill. +stream_set_write_buffer($client, 0); ShirabeRpcRuntime::$socket = $client; ShirabeRpcRuntime::$stubsDir = $argv[2] ?? null; -- cgit v1.3.1