Bug #71466 [NEW]: fopen php://input without reading from it terminates script output prematurely

From: Date: Wed, 27 Jan 2016 22:34:08 +0000
Subject: Bug #71466 [NEW]: fopen php://input without reading from it terminates script output prematurely
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198923@lists.php.net to get a copy of this message
From:             robin at mccorkell dot me dot uk
Operating system: Arch Linux x86_64
PHP version:      7.0.2
Package:          FPM related
Bug Type:         Bug
Bug description:fopen php://input without reading from it terminates script output prematurely

Description:
------------
This bug occurs only with php-fpm using the unix socket, mod_php and
php-fpm with TCP sockets were also tested and did not exhibit this bug.

When a script opens php://input for reading, then does not read from it,
the connection to any client is terminated early: cURL reports "transfer
closed with outstanding read data remaining", nginx reports "readv()
failed (104: Connection reset by peer) while reading upstream".

This also only occurs if some body has been sent with the request, so
GETs are unaffected, also it seems that POSTs are unaffected (contrast
with PUT, PATCH, PROPFIND etc which do have this issue).

To reproduce, set up an environment as described above, put the attached
test script in an accessible place, then run the following or
equivalent:

curl -i -X PROPFIND http://hostname/path/to/script.php -d "ping"

Downstream bug reports:

https://github.com/owncloud/core/issues/21935
https://stackoverflow.com/questions/34244406/readv-failed-on-propfind-request-while-reading-php-input-php-7-nginx

Test script:
---------------
<?php

$fh = fopen("php://input", "r");
echo "pong";

Expected result:
----------------
pong

Notice that removing the body (remove -d "ping" from the cURL line), or
reading some bytes from the php://input stream, or not opening the input
stream at all, will result in the expected "pong" response.

Actual result:
--------------
transfer closed with outstanding read data remaining

-- 
Edit bug report at https://bugs.php.net/bug.php?id=71466&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=71466&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=71466&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=71466&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=71466&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=71466&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=71466&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=71466&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=71466&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=71466&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=71466&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=71466&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=71466&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=71466&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71466&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=71466&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=71466&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=71466&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71466&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=71466&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=71466&r=mysqlcfg



Thread (3 messages)

« previous php.bugs (#198923) next »