Bug #53180 [Asn->Csd]: post_max_size=0 partly not working

From: Date: Wed, 27 Oct 2010 14:57:16 +0000
Subject: Bug #53180 [Asn->Csd]: post_max_size=0 partly not working
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-155567@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=53180&edit=1 ID: 53180 Updated by: cataphract@php.net Reported by: gm at tlink dot de Summary: post_max_size=0 partly not working -Status: Assigned +Status: Closed Type: Bug Package: PHP options/info functions Operating System: FreeBSD 8.1-RELEASE PHP Version: 5.3.3 Assigned To: cataphract Block user comment: N New Comment: This bug has been fixed in SVN. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2010-10-27 16:56:52] cataphract@php.net Automatic comment from SVN on behalf of cataphract Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=304958 Log: - Fixed bug #53180 (post_max_size=0 not disabling the limit when the content type is application/x-www-form-urlencoded or is not registered with PHP). ------------------------------------------------------------------------ [2010-10-27 11:25:32] gm at tlink dot de Description: ------------ Setting php.ini option post_max_size=0 (for unlimited POSTs since 5.3.2) isn't honoured in some cases. Doing a POST-form upload via curl or browser with a 5GB file works as expected (by setting upload_max_filesize=0 too) but using a login form (see below) results in this error: PHP Warning: Unknown: POST Content-Length of 38 bytes exceeds the limit of 0 bytes in Unknown on line 0 It seems that main/SAPI.c lacks checks in SAPI_POST_READER_FUNC() for ignoring size checking in case post_max_size==0. This check was implemented in main/rfc1867.c only. from: if (SG(request_info).content_length > S (post_max_size)) to: if (SG(post_max_size) > 0 && SG(request_info).content_length > S (post_max_size)) and from: if (SG(read_post_bytes) > SG(post_max_size)) to: if (SG(post_max_size) > 0 && SG(read_post_bytes) > SG(post_max_size)) Sorry for not attaching a diff yet. Gregor Test script: --------------- Loginform: <html><body> <form enctype="application/x-www-form-urlencoded" accept-charset="UTF-8" action="/login.php" method="post"> <input type="text" name="email" value="foo" /> <input type="password" name="password" value="bar" /> <input type="submit" name="submit" value="Log on" /> </form> </body></html> pointing to this login.php: <?php echo "Loginname: ".$_POST['email'] .'<br>'; echo "Password: ".$_POST['password']; ?> Expected result: ---------------- Loginname: foo Password: bar Actual result: -------------- Loginname: Password: ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/bug.php?id=53180&edit=1

« previous php.bugs (#155567) next »