Bug #69461 [NEW]: No file_get_contents() timeout if follow_location=false

From: Date: Wed, 15 Apr 2015 10:17:46 +0000
Subject: Bug #69461 [NEW]: No file_get_contents() timeout if follow_location=false
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192086@lists.php.net to get a copy of this message
From: marc at gutt dot it Operating system: Debian PHP version: 5.4.39 Package: URL related Bug Type: Bug Bug description:No file_get_contents() timeout if follow_location=false Description: ------------ I loaded several thousand http/https URLs through file_get_contents(). By that a very tiny amount of URLs did not respect the timeout setting of file_get_contents() and not the PHP max_execution_time as well. It results after 10 minutes an Internal Server Error. The problematic URL is a https://-URL that answers with a 301 redirect to a http://-URL. I tested it through cURL (CURLOPT_FOLLOWLOCATION=false,CURLOPT_SSL_VERIFYPEER=0), and this was the answer: ############################################### string(138) "HTTP/1.1 301 Moved Permanently Location: http://www.example.com/ Content-Length: 0 Content-Type: text/html; charset=UTF-8 " ############################################### More details here: http://stackoverflow.com/q/29628594/318765 Test script: --------------- this results "Internal Server Error" ############################################### $context = stream_context_create(array( 'http' => array( 'follow_location' => false, 'timeout' => 2, ), 'ssl' => array( 'verify_peer' => false, ), )); echo file_get_contents($url, false, $context); ############################################### this returns "Warning: file_get_contents(): SSL operation failed with code 1. OpenSSL Error messages: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed in /usr/www/users//t051.php on line 12": ############################################### 'verify_peer' => true, ############################################### And now the strange part. This returns the website?! ############################################### $context = stream_context_create(array( 'http' => array( 'follow_location' => true, 'timeout' => 2, ), 'ssl' => array( 'verify_peer' => false, ), )); echo file_get_contents($url, false, $context); ############################################### Expected result: ---------------- As verify_peer and follow_location are set to false it should return the websites header. Actual result: -------------- It returns "Internal Server Error 500" after 10 minutes. -- Edit bug report at https://bugs.php.net/bug.php?id=69461&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69461&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69461&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69461&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=69461&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=69461&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=69461&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=69461&r=needscript Try newer version: https://bugs.php.net/fix.php?id=69461&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=69461&r=support Expected behavior: https://bugs.php.net/fix.php?id=69461&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=69461&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=69461&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=69461&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69461&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=69461&r=dst IIS Stability: https://bugs.php.net/fix.php?id=69461&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=69461&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=69461&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=69461&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=69461&r=mysqlcfg

« previous php.bugs (#192086) next »