mirror of
https://github.com/danog/php.git
synced 2024-12-03 09:57:57 +01:00
e21810a050
The default signal used by docker to stop a container is SIGTERM and that signal is understood by PHP-FPM as immediate termination. This means that `php-fpm` won't wait for in-flight requests to finish before of stopping the workers and main process. This behaviour is quite undesired for production environments and should be avoided as much as possible. This implementation is meant to be extremely simple and only address the stop signal used when running `docker stop`. `php-fpm` signal choices are somewhat peculiar (`SIGUSR2` for example) and if we want to "fix" them we would have to use a tool (e.g.: `dumb-init`). More info: - https://linux.die.net/man/8/php-fpm - https://docs.docker.com/engine/reference/builder/#stopsignal - https://github.com/Yelp/dumb-init - https://github.com/usabilla/php-docker-template/pull/102
274 lines
8.5 KiB
Docker
274 lines
8.5 KiB
Docker
#
|
|
# NOTE: THIS DOCKERFILE IS GENERATED VIA "update.sh"
|
|
#
|
|
# PLEASE DO NOT EDIT IT DIRECTLY.
|
|
#
|
|
|
|
FROM debian:stretch-slim
|
|
|
|
# prevent Debian's PHP packages from being installed
|
|
# https://github.com/docker-library/php/pull/542
|
|
RUN set -eux; \
|
|
{ \
|
|
echo 'Package: php*'; \
|
|
echo 'Pin: release *'; \
|
|
echo 'Pin-Priority: -1'; \
|
|
} > /etc/apt/preferences.d/no-debian-php
|
|
|
|
# dependencies required for running "phpize"
|
|
# (see persistent deps below)
|
|
ENV PHPIZE_DEPS \
|
|
autoconf \
|
|
dpkg-dev \
|
|
file \
|
|
g++ \
|
|
gcc \
|
|
libc-dev \
|
|
make \
|
|
pkg-config \
|
|
re2c
|
|
|
|
# persistent / runtime deps
|
|
RUN apt-get update && apt-get install -y \
|
|
$PHPIZE_DEPS \
|
|
ca-certificates \
|
|
curl \
|
|
xz-utils \
|
|
--no-install-recommends && rm -r /var/lib/apt/lists/*
|
|
|
|
ENV PHP_INI_DIR /usr/local/etc/php
|
|
RUN set -eux; \
|
|
mkdir -p "$PHP_INI_DIR/conf.d"; \
|
|
# allow running as an arbitrary user (https://github.com/docker-library/php/issues/743)
|
|
[ ! -d /var/www/html ]; \
|
|
mkdir -p /var/www/html; \
|
|
chown www-data:www-data /var/www/html; \
|
|
chmod 777 /var/www/html
|
|
|
|
##<autogenerated>##
|
|
ENV PHP_EXTRA_CONFIGURE_ARGS --enable-fpm --with-fpm-user=www-data --with-fpm-group=www-data --disable-cgi
|
|
##</autogenerated>##
|
|
|
|
# Apply stack smash protection to functions using local buffers and alloca()
|
|
# Make PHP's main executable position-independent (improves ASLR security mechanism, and has no performance impact on x86_64)
|
|
# Enable optimization (-O2)
|
|
# Enable linker optimization (this sorts the hash buckets to improve cache locality, and is non-default)
|
|
# Adds GNU HASH segments to generated executables (this is used if present, and is much faster than sysv hash; in this configuration, sysv hash is also generated)
|
|
# https://github.com/docker-library/php/issues/272
|
|
ENV PHP_CFLAGS="-fstack-protector-strong -fpic -fpie -O2"
|
|
ENV PHP_CPPFLAGS="$PHP_CFLAGS"
|
|
ENV PHP_LDFLAGS="-Wl,-O1 -Wl,--hash-style=both -pie"
|
|
|
|
ENV GPG_KEYS CBAF69F173A0FEA4B537F470D66C9593118BCCB6 F38252826ACD957EF380D39F2F7956BC5DA04B5D
|
|
|
|
ENV PHP_VERSION 7.3.4
|
|
ENV PHP_URL="https://www.php.net/get/php-7.3.4.tar.xz/from/this/mirror" PHP_ASC_URL="https://www.php.net/get/php-7.3.4.tar.xz.asc/from/this/mirror"
|
|
ENV PHP_SHA256="6fe79fa1f8655f98ef6708cde8751299796d6c1e225081011f4104625b923b83" PHP_MD5=""
|
|
|
|
RUN set -xe; \
|
|
\
|
|
fetchDeps=' \
|
|
wget \
|
|
'; \
|
|
if ! command -v gpg > /dev/null; then \
|
|
fetchDeps="$fetchDeps \
|
|
dirmngr \
|
|
gnupg \
|
|
"; \
|
|
fi; \
|
|
apt-get update; \
|
|
apt-get install -y --no-install-recommends $fetchDeps; \
|
|
rm -rf /var/lib/apt/lists/*; \
|
|
\
|
|
mkdir -p /usr/src; \
|
|
cd /usr/src; \
|
|
\
|
|
wget -O php.tar.xz "$PHP_URL"; \
|
|
\
|
|
if [ -n "$PHP_SHA256" ]; then \
|
|
echo "$PHP_SHA256 *php.tar.xz" | sha256sum -c -; \
|
|
fi; \
|
|
if [ -n "$PHP_MD5" ]; then \
|
|
echo "$PHP_MD5 *php.tar.xz" | md5sum -c -; \
|
|
fi; \
|
|
\
|
|
if [ -n "$PHP_ASC_URL" ]; then \
|
|
wget -O php.tar.xz.asc "$PHP_ASC_URL"; \
|
|
export GNUPGHOME="$(mktemp -d)"; \
|
|
for key in $GPG_KEYS; do \
|
|
gpg --batch --keyserver ha.pool.sks-keyservers.net --recv-keys "$key"; \
|
|
done; \
|
|
gpg --batch --verify php.tar.xz.asc php.tar.xz; \
|
|
command -v gpgconf > /dev/null && gpgconf --kill all; \
|
|
rm -rf "$GNUPGHOME"; \
|
|
fi; \
|
|
\
|
|
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false $fetchDeps
|
|
|
|
COPY docker-php-source /usr/local/bin/
|
|
|
|
RUN set -eux; \
|
|
\
|
|
savedAptMark="$(apt-mark showmanual)"; \
|
|
apt-get update; \
|
|
apt-get install -y --no-install-recommends \
|
|
libcurl4-openssl-dev \
|
|
libedit-dev \
|
|
libsodium-dev \
|
|
libsqlite3-dev \
|
|
libssl-dev \
|
|
libxml2-dev \
|
|
zlib1g-dev \
|
|
${PHP_EXTRA_BUILD_DEPS:-} \
|
|
; \
|
|
##<argon2>##
|
|
sed -e 's/stretch/buster/g' /etc/apt/sources.list > /etc/apt/sources.list.d/buster.list; \
|
|
{ \
|
|
echo 'Package: *'; \
|
|
echo 'Pin: release n=buster'; \
|
|
echo 'Pin-Priority: -10'; \
|
|
echo; \
|
|
echo 'Package: libargon2*'; \
|
|
echo 'Pin: release n=buster'; \
|
|
echo 'Pin-Priority: 990'; \
|
|
} > /etc/apt/preferences.d/argon2-buster; \
|
|
apt-get update; \
|
|
apt-get install -y --no-install-recommends libargon2-dev; \
|
|
##</argon2>##
|
|
rm -rf /var/lib/apt/lists/*; \
|
|
\
|
|
export \
|
|
CFLAGS="$PHP_CFLAGS" \
|
|
CPPFLAGS="$PHP_CPPFLAGS" \
|
|
LDFLAGS="$PHP_LDFLAGS" \
|
|
; \
|
|
docker-php-source extract; \
|
|
cd /usr/src/php; \
|
|
gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)"; \
|
|
debMultiarch="$(dpkg-architecture --query DEB_BUILD_MULTIARCH)"; \
|
|
# https://bugs.php.net/bug.php?id=74125
|
|
if [ ! -d /usr/include/curl ]; then \
|
|
ln -sT "/usr/include/$debMultiarch/curl" /usr/local/include/curl; \
|
|
fi; \
|
|
./configure \
|
|
--build="$gnuArch" \
|
|
--with-config-file-path="$PHP_INI_DIR" \
|
|
--with-config-file-scan-dir="$PHP_INI_DIR/conf.d" \
|
|
\
|
|
# make sure invalid --configure-flags are fatal errors intead of just warnings
|
|
--enable-option-checking=fatal \
|
|
\
|
|
# https://github.com/docker-library/php/issues/439
|
|
--with-mhash \
|
|
\
|
|
# --enable-ftp is included here because ftp_ssl_connect() needs ftp to be compiled statically (see https://github.com/docker-library/php/issues/236)
|
|
--enable-ftp \
|
|
# --enable-mbstring is included here because otherwise there's no way to get pecl to use it properly (see https://github.com/docker-library/php/issues/195)
|
|
--enable-mbstring \
|
|
# --enable-mysqlnd is included here because it's harder to compile after the fact than extensions are (since it's a plugin for several extensions, not an extension in itself)
|
|
--enable-mysqlnd \
|
|
# https://wiki.php.net/rfc/argon2_password_hash (7.2+)
|
|
--with-password-argon2 \
|
|
# https://wiki.php.net/rfc/libsodium
|
|
--with-sodium=shared \
|
|
\
|
|
--with-curl \
|
|
--with-libedit \
|
|
--with-openssl \
|
|
--with-zlib \
|
|
\
|
|
# bundled pcre does not support JIT on s390x
|
|
# https://manpages.debian.org/stretch/libpcre3-dev/pcrejit.3.en.html#AVAILABILITY_OF_JIT_SUPPORT
|
|
$(test "$gnuArch" = 's390x-linux-gnu' && echo '--without-pcre-jit') \
|
|
--with-libdir="lib/$debMultiarch" \
|
|
\
|
|
${PHP_EXTRA_CONFIGURE_ARGS:-} \
|
|
; \
|
|
make -j "$(nproc)"; \
|
|
find -type f -name '*.a' -delete; \
|
|
make install; \
|
|
find /usr/local/bin /usr/local/sbin -type f -executable -exec strip --strip-all '{}' + || true; \
|
|
make clean; \
|
|
\
|
|
# https://github.com/docker-library/php/issues/692 (copy default example "php.ini" files somewhere easily discoverable)
|
|
cp -v php.ini-* "$PHP_INI_DIR/"; \
|
|
\
|
|
cd /; \
|
|
docker-php-source delete; \
|
|
\
|
|
# reset apt-mark's "manual" list so that "purge --auto-remove" will remove all build dependencies
|
|
apt-mark auto '.*' > /dev/null; \
|
|
[ -z "$savedAptMark" ] || apt-mark manual $savedAptMark; \
|
|
find /usr/local -type f -executable -exec ldd '{}' ';' \
|
|
| awk '/=>/ { print $(NF-1) }' \
|
|
| sort -u \
|
|
| xargs -r dpkg-query --search \
|
|
| cut -d: -f1 \
|
|
| sort -u \
|
|
| xargs -r apt-mark manual \
|
|
; \
|
|
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \
|
|
\
|
|
php --version; \
|
|
\
|
|
# https://github.com/docker-library/php/issues/443
|
|
pecl update-channels; \
|
|
rm -rf /tmp/pear ~/.pearrc
|
|
|
|
COPY docker-php-ext-* docker-php-entrypoint /usr/local/bin/
|
|
|
|
# sodium was built as a shared module (so that it can be replaced later if so desired), so let's enable it too (https://github.com/docker-library/php/issues/598)
|
|
RUN docker-php-ext-enable sodium
|
|
|
|
ENTRYPOINT ["docker-php-entrypoint"]
|
|
##<autogenerated>##
|
|
WORKDIR /var/www/html
|
|
|
|
RUN set -ex \
|
|
&& cd /usr/local/etc \
|
|
&& if [ -d php-fpm.d ]; then \
|
|
# for some reason, upstream's php-fpm.conf.default has "include=NONE/etc/php-fpm.d/*.conf"
|
|
sed 's!=NONE/!=!g' php-fpm.conf.default | tee php-fpm.conf > /dev/null; \
|
|
cp php-fpm.d/www.conf.default php-fpm.d/www.conf; \
|
|
else \
|
|
# PHP 5.x doesn't use "include=" by default, so we'll create our own simple config that mimics PHP 7+ for consistency
|
|
mkdir php-fpm.d; \
|
|
cp php-fpm.conf.default php-fpm.d/www.conf; \
|
|
{ \
|
|
echo '[global]'; \
|
|
echo 'include=etc/php-fpm.d/*.conf'; \
|
|
} | tee php-fpm.conf; \
|
|
fi \
|
|
&& { \
|
|
echo '[global]'; \
|
|
echo 'error_log = /proc/self/fd/2'; \
|
|
echo; echo '; https://github.com/docker-library/php/pull/725#issuecomment-443540114'; echo 'log_limit = 8192'; \
|
|
echo; \
|
|
echo '[www]'; \
|
|
echo '; if we send this to /proc/self/fd/1, it never appears'; \
|
|
echo 'access.log = /proc/self/fd/2'; \
|
|
echo; \
|
|
echo 'clear_env = no'; \
|
|
echo; \
|
|
echo '; Ensure worker stdout and stderr are sent to the main error log.'; \
|
|
echo 'catch_workers_output = yes'; \
|
|
echo 'decorate_workers_output = no'; \
|
|
} | tee php-fpm.d/docker.conf \
|
|
&& { \
|
|
echo '[global]'; \
|
|
echo 'daemonize = no'; \
|
|
echo; \
|
|
echo '[www]'; \
|
|
echo 'listen = 9000'; \
|
|
} | tee php-fpm.d/zz-docker.conf
|
|
|
|
EXPOSE 9000
|
|
|
|
# Override stop signal to stop process gracefully
|
|
#
|
|
# https://github.com/php/php-src/blob/17baa87faddc2550def3ae7314236826bc1b1398/sapi/fpm/php-fpm.8.in#L163
|
|
STOPSIGNAL SIGQUIT
|
|
|
|
CMD ["php-fpm"]
|
|
##</autogenerated>##
|