Bug #53180 [Asn->Csd]: post_max_size=0 partly not working
| From: | cataphract@php.net | Date: | Wed, 27 Oct 2010 14:57:16 +0000 |
| Subject: | Bug #53180 [Asn->Csd]: post_max_size=0 partly not working | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-155567@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=53180&edit=1
ID: 53180
Updated by: cataphract@php.net
Reported by: gm at tlink dot de
Summary: post_max_size=0 partly not working
-Status: Assigned
+Status: Closed
Type: Bug
Package: PHP options/info functions
Operating System: FreeBSD 8.1-RELEASE
PHP Version: 5.3.3
Assigned To: cataphract
Block user comment: N
New Comment:
This bug has been fixed in SVN.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2010-10-27 16:56:52] cataphract@php.net
Automatic comment from SVN on behalf of cataphract
Revision: http://svn.php.net/viewvc/?view=revision&revision=304958
Log: - Fixed bug #53180 (post_max_size=0 not disabling the limit when
the content
type is application/x-www-form-urlencoded or is not registered with
PHP).
------------------------------------------------------------------------
[2010-10-27 11:25:32] gm at tlink dot de
Description:
------------
Setting php.ini option post_max_size=0 (for unlimited POSTs since 5.3.2)
isn't honoured in some cases. Doing a POST-form upload via curl or
browser with a 5GB file works as expected (by setting
upload_max_filesize=0 too) but using a login form (see below) results in
this error:
PHP Warning: Unknown: POST Content-Length of 38 bytes exceeds the limit
of 0 bytes in Unknown on line 0
It seems that main/SAPI.c lacks checks in SAPI_POST_READER_FUNC() for
ignoring size checking in case post_max_size==0. This check was
implemented in main/rfc1867.c only.
from: if (SG(request_info).content_length > S (post_max_size))
to: if (SG(post_max_size) > 0 && SG(request_info).content_length > S
(post_max_size))
and
from: if (SG(read_post_bytes) > SG(post_max_size))
to: if (SG(post_max_size) > 0 && SG(read_post_bytes) >
SG(post_max_size))
Sorry for not attaching a diff yet.
Gregor
Test script:
---------------
Loginform:
<html><body>
<form enctype="application/x-www-form-urlencoded" accept-charset="UTF-8"
action="/login.php" method="post">
<input type="text" name="email" value="foo" />
<input type="password" name="password" value="bar" />
<input type="submit" name="submit" value="Log on" />
</form>
</body></html>
pointing to this login.php:
<?php
echo "Loginname: ".$_POST['email'] .'<br>';
echo "Password: ".$_POST['password'];
?>
Expected result:
----------------
Loginname: foo
Password: bar
Actual result:
--------------
Loginname:
Password:
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=53180&edit=1