Bug #69088 [Opn->Fbk]: PHP_MINIT_FUNCTION does not fully initialize cURL on Win32

From: Date: Sat, 21 Feb 2015 17:35:35 +0000
Subject: Bug #69088 [Opn->Fbk]: PHP_MINIT_FUNCTION does not fully initialize cURL on Win32
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190870@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69088&edit=1

 ID:                 69088
 Updated by:         ab@php.net
 Reported by:        grant at digitaldj dot net
 Summary:            PHP_MINIT_FUNCTION does not fully initialize cURL on
                     Win32
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            cURL related
 Operating System:   Windows (all)
 PHP Version:        5.6.6
 Block user comment: N
 Private report:     N

 New Comment:

@grant, thanks for the patch. I've a couple of questions.

- you say that won't affect any non windows platforms, however the code isn't
#ifdef'ed ... so looks like it could affect other platforms. Refering to http://curl.haxx.se/libcurl/c/curl_global_init.html
, you mean CURL_GLOBAL_DEFAULT will init both CURL_GLOBAL_SSL and win32
- i've checked the same on master, but got no crash there ... wondering if you could check that
as well
- were it possible to add some test for this?

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2015-02-20 12:14:53] grant at digitaldj dot net

Description:
------------
Since cURL 7.40.0, HTTP Digest Authentication support is now handled by Windows SSPI.

To initialize cURL, the php_curl module uses curl_global_init(CURL_GLOBAL_SSL); This call skips
initializing any Win32 specific features (see curl_global_init in cURL lib/easy.c). 

As a result, the SSPI interface is not initialized and attempting to use HTTP Digest Authentication
results in referencing a null pointer, s_pSecFn, in Curl_sasl_create_digest_http_message
(lib/curl_sasl_sspi.c).

To fix, PHP_MINIT_FUNCTION should call curl_global_init with CURL_GLOBAL_DEFAULT. This will not
affect non-Win32 platforms and is the cURL recommended default.

This was tested with the official Windows PHP binaries, 5.6.6 VC11 x86 Thread Safe, running on
Windows 8.1 x64.



Test script:
---------------
<?php
$url = "http://httpbin.org/digest-auth/auth/user/passwd";
$userPass = "user:pass";
$curl = curl_init($url);
curl_setopt($curl, CURLOPT_VERBOSE, true);
curl_setopt($curl, CURLOPT_USERPWD, $userPass);
curl_setopt($curl, CURLOPT_HTTPAUTH, CURLAUTH_DIGEST);
$response = curl_exec($curl);
curl_close($curl);
?>

Expected result:
----------------
cURL successfully sends a request to the server and PHP exits with code 0.

Actual result:
--------------
PHP crahes with null pointer reference s_pSecFn, in Curl_sasl_create_digest_http_message
(lib/curl_sasl_sspi.c)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69088&edit=1


Thread (7 messages)

« previous php.bugs (#190870) next »