Bug #69088 [Com]: PHP_MINIT_FUNCTION does not fully initialize cURL on Win32
Edit report at https://bugs.php.net/bug.php?id=69088&edit=1
ID: 69088
Comment by: grant at digitaldj dot net
Reported by: grant at digitaldj dot net
Summary: PHP_MINIT_FUNCTION does not fully initialize cURL on
Win32
Status: Feedback
Type: Bug
Package: cURL related
Operating System: Windows (all)
PHP Version: 5.6.6
Block user comment: N
Private report: N
New Comment:
Hi,
The code is in fact #ifdef'd. The code calls win32_init() but all code within that function is
appropriately #ifdef'd (all of this is in cURL's lib/easy.c).
From a maintainability point of view, going with CURL_GLOBAL_DEFAULT is the best action. Even the
curl binary on Linux initializes with CURL_GLOBAL_DEFAULT.
The alternative however, is to compile cURL without USE_WINDOWS_SSPI. This falls back to the
Unix-method of manually parsing the HTTP Digest Challenge Message. The Windows SSPI code is then
avoided and the behavior of cURL more closely matches that of when running on Unix platforms.
As for master, I'm not sure. I'm having a little trouble getting it to compile with what I
have installed (VC12). But I'll give it my best shot. I've scoured the commits and I
can't see anything that would affect it....unless of course you are compiling cURL without
USE_WINDOWS_SSPI.
Cheers
Previous Comments:
------------------------------------------------------------------------
[2015-02-21 17:35:34] ab@php.net
@grant, thanks for the patch. I've a couple of questions.
- you say that won't affect any non windows platforms, however the code isn't
#ifdef'ed ... so looks like it could affect other platforms. Refering to http://curl.haxx.se/libcurl/c/curl_global_init.html
, you mean CURL_GLOBAL_DEFAULT will init both CURL_GLOBAL_SSL and win32
- i've checked the same on master, but got no crash there ... wondering if you could check that
as well
- were it possible to add some test for this?
Thanks.
------------------------------------------------------------------------
[2015-02-20 12:14:53] grant at digitaldj dot net
Description:
------------
Since cURL 7.40.0, HTTP Digest Authentication support is now handled by Windows SSPI.
To initialize cURL, the php_curl module uses curl_global_init(CURL_GLOBAL_SSL); This call skips
initializing any Win32 specific features (see curl_global_init in cURL lib/easy.c).
As a result, the SSPI interface is not initialized and attempting to use HTTP Digest Authentication
results in referencing a null pointer, s_pSecFn, in Curl_sasl_create_digest_http_message
(lib/curl_sasl_sspi.c).
To fix, PHP_MINIT_FUNCTION should call curl_global_init with CURL_GLOBAL_DEFAULT. This will not
affect non-Win32 platforms and is the cURL recommended default.
This was tested with the official Windows PHP binaries, 5.6.6 VC11 x86 Thread Safe, running on
Windows 8.1 x64.
Test script:
---------------
<?php
$url = "http://httpbin.org/digest-auth/auth/user/passwd";
$userPass = "user:pass";
$curl = curl_init($url);
curl_setopt($curl, CURLOPT_VERBOSE, true);
curl_setopt($curl, CURLOPT_USERPWD, $userPass);
curl_setopt($curl, CURLOPT_HTTPAUTH, CURLAUTH_DIGEST);
$response = curl_exec($curl);
curl_close($curl);
?>
Expected result:
----------------
cURL successfully sends a request to the server and PHP exits with code 0.
Actual result:
--------------
PHP crahes with null pointer reference s_pSecFn, in Curl_sasl_create_digest_http_message
(lib/curl_sasl_sspi.c)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69088&edit=1
Thread (7 messages)