Bug #69088 [Opn->Fbk]: PHP_MINIT_FUNCTION does not fully initialize cURL on Win32
Edit report at https://bugs.php.net/bug.php?id=69088&edit=1
ID: 69088
Updated by: ab@php.net
Reported by: grant at digitaldj dot net
Summary: PHP_MINIT_FUNCTION does not fully initialize cURL on
Win32
-Status: Open
+Status: Feedback
Type: Bug
Package: cURL related
Operating System: Windows (all)
PHP Version: 5.6.6
Block user comment: N
Private report: N
New Comment:
@grant, thanks for the patch. I've a couple of questions.
- you say that won't affect any non windows platforms, however the code isn't
#ifdef'ed ... so looks like it could affect other platforms. Refering to http://curl.haxx.se/libcurl/c/curl_global_init.html
, you mean CURL_GLOBAL_DEFAULT will init both CURL_GLOBAL_SSL and win32
- i've checked the same on master, but got no crash there ... wondering if you could check that
as well
- were it possible to add some test for this?
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2015-02-20 12:14:53] grant at digitaldj dot net
Description:
------------
Since cURL 7.40.0, HTTP Digest Authentication support is now handled by Windows SSPI.
To initialize cURL, the php_curl module uses curl_global_init(CURL_GLOBAL_SSL); This call skips
initializing any Win32 specific features (see curl_global_init in cURL lib/easy.c).
As a result, the SSPI interface is not initialized and attempting to use HTTP Digest Authentication
results in referencing a null pointer, s_pSecFn, in Curl_sasl_create_digest_http_message
(lib/curl_sasl_sspi.c).
To fix, PHP_MINIT_FUNCTION should call curl_global_init with CURL_GLOBAL_DEFAULT. This will not
affect non-Win32 platforms and is the cURL recommended default.
This was tested with the official Windows PHP binaries, 5.6.6 VC11 x86 Thread Safe, running on
Windows 8.1 x64.
Test script:
---------------
<?php
$url = "http://httpbin.org/digest-auth/auth/user/passwd";
$userPass = "user:pass";
$curl = curl_init($url);
curl_setopt($curl, CURLOPT_VERBOSE, true);
curl_setopt($curl, CURLOPT_USERPWD, $userPass);
curl_setopt($curl, CURLOPT_HTTPAUTH, CURLAUTH_DIGEST);
$response = curl_exec($curl);
curl_close($curl);
?>
Expected result:
----------------
cURL successfully sends a request to the server and PHP exits with code 0.
Actual result:
--------------
PHP crahes with null pointer reference s_pSecFn, in Curl_sasl_create_digest_http_message
(lib/curl_sasl_sspi.c)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69088&edit=1
Thread (7 messages)