Bug #71466 [Opn->Csd]: fopen php://input without reading from it terminates script output prematurely
| From: | laruence@php.net | Date: | Mon, 08 Feb 2016 03:05:39 +0000 |
| Subject: | Bug #71466 [Opn->Csd]: fopen php://input without reading from it terminates script output prematurely | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199105@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71466&edit=1
ID: 71466
Updated by: laruence@php.net
Reported by: robin at mccorkell dot me dot uk
Summary: fopen php://input without reading from it terminates
script output prematurely
-Status: Open
+Status: Closed
Type: Bug
Package: FPM related
Operating System: Arch Linux x86_64
PHP Version: 7.0.2
-Assigned To:
+Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2016-01-28 12:23:20] robin at mccorkell dot me dot uk
I did a bisect on the source, 18cf4e0a8a574034f60f4d123407c173e57e54ec is the breaking commit
------------------------------------------------------------------------
[2016-01-27 22:34:02] robin at mccorkell dot me dot uk
Description:
------------
This bug occurs only with php-fpm using the unix socket, mod_php and php-fpm with TCP sockets were
also tested and did not exhibit this bug.
When a script opens php://input for reading, then does not read from it, the connection to any
client is terminated early: cURL reports "transfer closed with outstanding read data
remaining", nginx reports "readv() failed (104: Connection reset by peer) while reading
upstream".
This also only occurs if some body has been sent with the request, so GETs are unaffected, also it
seems that POSTs are unaffected (contrast with PUT, PATCH, PROPFIND etc which do have this issue).
To reproduce, set up an environment as described above, put the attached test script in an
accessible place, then run the following or equivalent:
curl -i -X PROPFIND http://hostname/path/to/script.php -d "ping"
Downstream bug reports:
https://github.com/owncloud/core/issues/21935
https://stackoverflow.com/questions/34244406/readv-failed-on-propfind-request-while-reading-php-input-php-7-nginx
Test script:
---------------
<?php
$fh = fopen("php://input", "r");
echo "pong";
Expected result:
----------------
pong
Notice that removing the body (remove -d "ping" from the cURL line), or reading some bytes
from the php://input stream, or not opening the input stream at all, will result in the expected
"pong" response.
Actual result:
--------------
transfer closed with outstanding read data remaining
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71466&edit=1