php / php/php-src

Multiple entries for PHP-FPMs listen directive

未关闭
#11,593 1 条评论 2 个 reaction 已指派 1 人 在 GitHub 查看

@bukka 已经在做这个了。

开始于 2023年7月4日。

Feature SAPI: fpm Status: Needs Triage
主要语言
C
星标
40.4k
派生
8.1k
平均合并
2 天 13 小时
30 天内合并 PR
96

描述

Description

Currently, PHP-FPM provides limited options for defining the host address, restricting it to either no host, an IPv4 address, or an IPv6 address. Here are the existing configurations and their limitations:

  1. listen = 9000 (IPv4 and IPv6, but accessible from all sources)
    This configuration allows PHP-FPM to listen on both IPv4 and IPv6 addresses, but it lacks the ability to specify a particular host.

  2. listen = 127.0.0.1:9000 (accessible only locally via IPv4)
    PHP-FPM can be accessed locally using IPv4, but it does not support IPv6 connections.

  3. listen = [::1]:9000 (accessible only locally via IPv6)
    Enables local accessibility through IPv6, but it does not support IPv4 connections.

  4. listen = localhost:9000 (binds to IPv4 only)
    This configuration restricts PHP-FPM to bind exclusively to IPv4 in my case.

The current limitations force users to make compromises. One possible solution is to globally set PHP-FPM to listen on port 9000 and control access through firewall rules or the listen.allowed_clients directive. However, it is desirable to have firewall-independent configurations and ensure closed internet access.

To address this, I propose introducing support for multiple interfaces in the PHP-FPM configuration:

listen = 127.0.0.1:9000, [::1]:9000

This configuration would allow PHP-FPM to listen on both IPv4 (127.0.0.1) and IPv6 ([::1]) addresses simultaneously, providing full control over the interfaces while maintaining full backwards-compatibility.

Alternatively, another solution could involve introducing a "port" directive and making the port specification optional within the listen directive:

listen = 127.0.0.1, [::1]
port = 9000

By implementing either of these solutions, clients can choose the most suitable approach based on their requirements and preferences.

This enhancement would also allow system administrators - particularly nginx upstream users with split configurations - to use "localhost" as a reliable target and leave it up to nginx/dns resolver/system settings to determine the IP version instead of "hard-coding" it into dozens - if not hundred - of files.

Please kindly consider my request.

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。