Edit report at https://bugs.php.net/bug.php?id=69088&edit=1
ID: 69088
Updated by: ab@php.net
Reported by: grant at digitaldj dot net
Summary: PHP_MINIT_FUNCTION does not fully initialize cURL on
Win32
Status: Feedback
Type: Bug
Package: cURL related
Operating System: Windows (all)
PHP Version: 5.6.6
Block user comment: N
Private report: N
New Comment:
After looking at lib/easy.c - agreed, default is CURL_GLOBAL_SSL|CURL_GLOBAL_WIN32 and that's
just one empty call which will be optimized away, so that's fine. I also think it makes sense
to use SSPI. Still two things I'd ask you to do:
- it's probably safer to do curl version check on compile time, as it's unknown what
possible differences older versions have
- please rebase the PR against 5.5 as we use curl 7.40.0 there, too. Or i can backport it later
after merge, actually not a big deal (not sure it'll need to recreate a PR).
With master - probably other topic, but we still use VC11 for it. VC12 should work, however there
are no deps prepared (like you could fetch for VC11 from windows.php.net), so you'll need to do
that yourself. But in general - maybe you could report in some other ticket or on the mailing lists,
what the exact issues you met are.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2015-02-22 05:31:09] grant at digitaldj dot net
As for tests, the test script attached to the bug is the only decent way I can think of testing
whether cURL is compiled with USE_WINDOWS_SSPI. Unfortunately, it relies on a remote server.
------------------------------------------------------------------------
[2015-02-22 05:26:29] grant at digitaldj dot net
Hi,
The code is in fact #ifdef'd. The code calls win32_init() but all code within that function is
appropriately #ifdef'd (all of this is in cURL's lib/easy.c).
From a maintainability point of view, going with CURL_GLOBAL_DEFAULT is the best action. Even the
curl binary on Linux initializes with CURL_GLOBAL_DEFAULT.
The alternative however, is to compile cURL without USE_WINDOWS_SSPI. This falls back to the
Unix-method of manually parsing the HTTP Digest Challenge Message. The Windows SSPI code is then
avoided and the behavior of cURL more closely matches that of when running on Unix platforms.
As for master, I'm not sure. I'm having a little trouble getting it to compile with what I
have installed (VC12). But I'll give it my best shot. I've scoured the commits and I
can't see anything that would affect it....unless of course you are compiling cURL without
USE_WINDOWS_SSPI.
Cheers
------------------------------------------------------------------------
[2015-02-21 17:35:34] ab@php.net
@grant, thanks for the patch. I've a couple of questions.
- you say that won't affect any non windows platforms, however the code isn't
#ifdef'ed ... so looks like it could affect other platforms. Refering to http://curl.haxx.se/libcurl/c/curl_global_init.html
, you mean CURL_GLOBAL_DEFAULT will init both CURL_GLOBAL_SSL and win32
- i've checked the same on master, but got no crash there ... wondering if you could check that
as well
- were it possible to add some test for this?
Thanks.
------------------------------------------------------------------------
[2015-02-20 12:14:53] grant at digitaldj dot net
Description:
------------
Since cURL 7.40.0, HTTP Digest Authentication support is now handled by Windows SSPI.
To initialize cURL, the php_curl module uses curl_global_init(CURL_GLOBAL_SSL); This call skips
initializing any Win32 specific features (see curl_global_init in cURL lib/easy.c).
As a result, the SSPI interface is not initialized and attempting to use HTTP Digest Authentication
results in referencing a null pointer, s_pSecFn, in Curl_sasl_create_digest_http_message
(lib/curl_sasl_sspi.c).
To fix, PHP_MINIT_FUNCTION should call curl_global_init with CURL_GLOBAL_DEFAULT. This will not
affect non-Win32 platforms and is the cURL recommended default.
This was tested with the official Windows PHP binaries, 5.6.6 VC11 x86 Thread Safe, running on
Windows 8.1 x64.
Test script:
---------------
<?php
$url = "http://httpbin.org/digest-auth/auth/user/passwd";
$userPass = "user:pass";
$curl = curl_init($url);
curl_setopt($curl, CURLOPT_VERBOSE, true);
curl_setopt($curl, CURLOPT_USERPWD, $userPass);
curl_setopt($curl, CURLOPT_HTTPAUTH, CURLAUTH_DIGEST);
$response = curl_exec($curl);
curl_close($curl);
?>
Expected result:
----------------
cURL successfully sends a request to the server and PHP exits with code 0.
Actual result:
--------------
PHP crahes with null pointer reference s_pSecFn, in Curl_sasl_create_digest_http_message
(lib/curl_sasl_sspi.c)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69088&edit=1