Bug #69487 [NEW]: SAPI may cause truncated POST data

From: Date: Mon, 20 Apr 2015 10:21:47 +0000
Subject: Bug #69487 [NEW]: SAPI may cause truncated POST data
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192235@lists.php.net to get a copy of this message
From: erik at datahack dot se Operating system: PHP version: Irrelevant Package: *Web Server problem Bug Type: Bug Bug description:SAPI may cause truncated POST data Description: ------------ If the SAPI fails to write the POST data to disk (eg. due to file system full or tmp folder is non-writable for other reasons), The PHP interpreter will get an incomplete/truncated POST request. This is very bad for data consistency if data is lost upon POST. One workaround in the PHP script would be to check the content-length against the length of php://input. if (count($_POST) && (int)$_SERVER['CONTENT_LENGTH'] != strlen(file_get_contents("php://input"))) ... display_startup_errors triggers only a warning if the file can't be created (but the data is still corrupted). There are two cases that can happen and shouldn't result in corrupt data. 1. Temp file cannot be created 2. Data cannot be written to temp file https://github.com/php/php-src/blob/master/main/SAPI.c#L288 Test script: --------------- If sys_temp_dir can't be written to this will cause corrupt data. <?php if (count($_POST)) { echo strlen(file_get_contents("php://input"))."<br>"; echo file_get_contents("php://input")."<br>"; } ?> <form method="post"> <input type="hidden" name="data" value="<?php echo str_repeat("x", 16384).str_repeat("y", 16384).str_repeat("z", 16384); ?>"> <input type="submit"> </form> Expected result: ---------------- No POST data or an internal error would be better than just continue with corrupt data... Actual result: -------------- PHP continues to process the request with corrupt data. -- Edit bug report at https://bugs.php.net/bug.php?id=69487&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69487&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69487&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69487&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=69487&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=69487&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=69487&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=69487&r=needscript Try newer version: https://bugs.php.net/fix.php?id=69487&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=69487&r=support Expected behavior: https://bugs.php.net/fix.php?id=69487&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=69487&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=69487&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=69487&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69487&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=69487&r=dst IIS Stability: https://bugs.php.net/fix.php?id=69487&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=69487&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=69487&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=69487&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=69487&r=mysqlcfg

« previous php.bugs (#192235) next »