Bug #64187 [Fbk->Asn]: CGI/FastCGI truncates input to modulo 4GB

From: Date: Wed, 16 Jul 2014 21:20:06 +0000
Subject: Bug #64187 [Fbk->Asn]: CGI/FastCGI truncates input to modulo 4GB
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186676@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64187&edit=1

 ID:                 64187
 User updated by:    nachms+php at gmail dot com
 Reported by:        nachms+php at gmail dot com
 Summary:            CGI/FastCGI truncates input to modulo 4GB
-Status:             Feedback
+Status:             Assigned
 Type:               Bug
 Package:            Streams related
 Operating System:   Linux
 PHP Version:        5.6
 Assigned To:        mike
 Block user comment: N
 Private report:     N

 New Comment:

I played more with 5.6, finding it odd that we're being limited to ~1.7GB (which seems to have
no mathematical significance), whereas in PHP 5.3-5.5, we were seeing the size upload capped to
Content-Length%4GB.

Then I noticed that's how much free space is available in /tmp on our test server.

In PHP < 5.6, uploads via PUT were streamed, so the PHP script could save wherever it wanted to
as it was being uploaded, or stream the data into a database or remote server, or just run some
formulas on the data without storing any of raw PUT data.

In PHP 5.6, it seems the truncation bug has been corrected, but in the process the data is no longer
streamable, making it difficult to effectively deal with huge files, introducing issues into past
cases that worked (because they were <4GB).

Is there a way to tell PHP 5.6 to not buffer/save uploads via PUT? PUT, unlike POST doesn't
need PHP to parse the data to put into the various superglobals.


Previous Comments:
------------------------------------------------------------------------
[2014-07-16 19:57:59] mike@php.net

Please try with a source build.
I've no problems POSTing or PUTting files of size 10G.

█ mike@smugmug:~/tmp$ l -hl 10G
-rw-r--r-- 1 mike users 9.8G  1. Jul 21:44 10G
█ mike@smugmug:~/tmp$ cat /srv/http/put.php
<?php

$tmp = tempnam("/var/tmp", "put");
var_dump(file_put_contents($tmp, fopen("php://input","r")), filesize($tmp),
unlink($tmp));

█ mike@smugmug:~/build/php-5.6-dbg$ ./sapi/cgi/php-cgi -b 0:9999 -d post_max_size=99G -d
upload_max_filesize=99G

█ mike@smugmug:~/tmp$ curl -v --upload-file ~/tmp/10G http://localhost:88/put.php
* Hostname was NOT found in DNS cache
*   Trying ::1...
* connect to ::1 port 88 failed: Connection refused
*   Trying 127.0.0.1...
* Connected to localhost (127.0.0.1) port 88 (#0)
> PUT /put.php HTTP/1.1
> User-Agent: curl/7.37.0
> Host: localhost:88
> Accept: */*
> Content-Length: 10485760000
> Expect: 100-continue
> 
< HTTP/1.1 100 Continue
* We are completely uploaded and fine


< HTTP/1.1 200 OK
* Server nginx/1.6.0 is not blacklisted
< Server: nginx/1.6.0
< Date: Wed, 16 Jul 2014 19:47:33 GMT
< Content-Type: text/html; charset=UTF-8
< Transfer-Encoding: chunked
< Connection: keep-alive
< X-Powered-By: PHP/5.6.0-dev
< 
int(10485760000)
int(10485760000)
bool(true)
* Connection #0 to host localhost left intact

------------------------------------------------------------------------
[2014-07-15 22:06:37] nachms+php at gmail dot com

Yes, as I said in my previous post, it fails in php5-cgi_5.6.0~rc2+dfsg-3_amd64.deb, which as far as
I know is "5.6 or later".

Amount Read: 1374904320 (Should be Amount Read: 4296015872)
Was only able to send 1374978048 bytes. (Should not get this error)

------------------------------------------------------------------------
[2014-07-15 22:01:43] yohgaki@php.net

Starting from 5.6, PHP handles large 'php://input' and makes 'php://input'
reusable. This change will not be backported to older versions.

If this is fixed in 5.6, this bug should be closed.
Do you still have problem in 5.6 or later?

------------------------------------------------------------------------
[2014-07-13 11:09:16] nachms+php at gmail dot com

Okay, I found a binary at: http://ftp.us.debian.org/debian/pool/main/p/php5/php5-cgi_5.6.0~rc2+dfsg-3_amd64.deb

I'm now getting different results than 5.3, 5.4, and 5.5, but it still fails.

Amount Read: 1374904320 (Should be Amount Read: 4296015872)
Was only able to send 1374978048 bytes. (Should not get this error)

------------------------------------------------------------------------
[2014-07-13 11:02:10] nachms+php at gmail dot com

I don't have any version of 5.6 handy. It seems official downloads are supposed to be at http://qa.php.net/, but for some reason, that site isn't loading
for me. Is there an alternate location to download 5.6 from?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=64187


--
Edit this bug report at https://bugs.php.net/bug.php?id=64187&edit=1


Thread (26 messages)

« previous php.bugs (#186676) next »