Edit report at https://bugs.php.net/bug.php?id=71861&edit=1
ID: 71861
Updated by: ab@php.net
Reported by: paul at salesintel dot com
Summary: Buffer Overrun in curl_exec() causing hang
-Status: Open
+Status: Closed
Type: Bug
Package: cURL related
Operating System: Windows 10 x64
PHP Version: 7.0.4
-Assigned To:
+Assigned To: ab
Block user comment: N
Private report: N
New Comment:
@paul thanks for the checks, I've uploaded the builds to the same location.
It's not a PHP issue, the hang was happening inside libcurl. You can read about more details in
the github ticket i've linked above. We'll be checking to upgrade when the next cURL
version is available, for now the patched 7.47.1 can be used.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2016-04-03 17:19:35] paul at salesintel dot com
The repro() function now completes in all cases (although supplied arguments are invalid garbage).
I removed my workaround in my actual project, where similar curl_* calls occur (but with valid
parameters), and all appears to be working as expected.
I'm still curious, in the original php_curl version, why PHP hung rather than throwing an
Exception.
Regardless, thanks @ab@php.net so much for resolving.
-paul
p.s. we're using the non-thread-safe 32b & 64b versions of php. Any chance of getting a
(hot)fixed build for those configurations?
------------------------------------------------------------------------
[2016-04-02 09:48:57] ab@php.net
@paul could you please check whether this build fixes the issue for you? http://windows.php.net/downloads/snaps/ostc/71861/
. Just drop it into the ext folder and activate in the php.ini instead of the php_curl.dll .
Thanks.
------------------------------------------------------------------------
[2016-03-30 14:47:55] ab@php.net
Till now it looks indeed like a libcurl issue, a simple program can reproduce the same behavior https://gist.github.com/weltling/15400de1018c7e6a4b476a415f08768d
. I filed an issue to the upstream on github https://github.com/curl/curl/issues/741 .
Thanks.
------------------------------------------------------------------------
[2016-03-30 12:02:14] ab@php.net
I was able to reproduce the hang now. Both latest 5.6 and 7 reproduce, both use libcurl 7.47.1 on
Windows. A step through shows, that where it hangs is curl_easy_perform(), around interface.c:2880
in 7.0;
So how it looks like, it is either a bug or a behavior change in libcurl. 7.48.0 show it as well,
7.42.1 doesn't. I currently don't see any suspicious commits to ext/libcurl that could
cause this regression. Will check with a small C program whether it behaves same.
Thanks.
------------------------------------------------------------------------
[2016-03-28 19:55:12] nikic@php.net
Curl confirmed that these warnings are indirectly caused by openssl, so we can ignore those.
I was not able to reproduce the original issue on Ubuntu 14.04.
I am able to reproduce the hang on Windows, but cannot help beyond that.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71861
--
Edit this bug report at https://bugs.php.net/bug.php?id=71861&edit=1