Bug #70315 [Asn->Ana]: imagecreatefromstring() returns 500 Server Error but page is fully rendered

From: Date: Thu, 07 Jul 2016 12:56:02 +0000
Subject: Bug #70315 [Asn->Ana]: imagecreatefromstring() returns 500 Server Error but page is fully rendered
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202119@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70315&edit=1

 ID:                 70315
 Updated by:         cmb@php.net
 Reported by:        patriciotarantino at gmail dot com
 Summary:            imagecreatefromstring() returns 500 Server Error but
                     page is fully rendered
-Status:             Assigned
+Status:             Analyzed
 Type:               Bug
 Package:            GD related
 Operating System:   Ubuntu
 PHP Version:        5.6.12
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Okay, I'am able to reproduce the reported behavior now. It happens
only when an external libgd is used, not with PHP's bundled libgd.

> PHP Unknown error:  imagecreatefromstring(): gd-png: fatal […]
> PHP Parse error:  imagecreatefromstring(): gd-png error: […]

That's the crux. The bundled libgd reports instead:

| Warning: imagecreatefromstring(): gd-png: fatal […]
| Warning: imagecreatefromstring(): gd-png error: […]

One culprit is php_gd_error_method()[1] which simply forwards to
php_verror() without adjusting the type argument, although libgd
uses other error codes than PHP (for instance, GD_ERROR is 3,
which is unknown to PHP). While a simple mapping of the error
codes would solve this problem, it still would cause different
behavior depending whether the bundled or an external libgd is
used. In this case the bundled libgd would raise warnings only and
simply go on, while an external libgd would raise errors and abort
the script.

As changing libgd obviously isn't an option due to the ABI break,
we probably should change PHP's bundled libgd (i.e. raise E_ERROR
instead of E_WARNING), but that would cause a BC break, so maybe
it's best to do that only for PHP 7.1.0, and to accept the
different behavior for older versions. php_gd_error_method(),
however, should be fixed for PHP 5.6+.

I'll prepare a PR.


[1] <https://github.com/php/php-src/blob/php-7.0.8/ext/gd/gd.c#L1021-L1025>


Previous Comments:
------------------------------------------------------------------------
[2016-07-04 14:17:37] razzari at gmail dot com

I can also repro with Nginx and FPM/FastCGI. 
PHP Version 5.5.9-1ubuntu4.17.
GD Version 2.1.1-dev.

------------------------------------------------------------------------
[2016-07-04 13:32:59] razzari at gmail dot com

This was mod_php (libapache2-mod-php5.6).

------------------------------------------------------------------------
[2016-07-04 11:25:43] cmb@php.net

> mod_apache

Of course I meant mod_php!

------------------------------------------------------------------------
[2016-07-04 11:25:02] cmb@php.net

@razzari Thanks for the detailed explanation. I'll try to
reproduce with your environement. Do you use FPM or mod_apache?

------------------------------------------------------------------------
[2016-07-03 22:27:00] razzari at gmail dot com

Here's the logs as text (Sorry, I had included them in the screenshot in the prev comment).

PHP Unknown error:  imagecreatefromstring(): gd-png: fatal libpng error: IHDR: CRC error\n in
Unknown on line 0
PHP Parse error:  imagecreatefromstring(): gd-png error: setjmp returns error condition 1\n in
/var/www/test.php on line 6
PHP Warning:  imagecreatefromstring(): Passed data is not in 'PNG' format in
/var/www/test.php on line 6
PHP Warning:  imagecreatefromstring(): Couldn't create GD Image Stream out of Data in
/var/www/test.php on line 6

I can repro this consistently.

Please let me know if I can provide further info/tests. 

This is a barebones install in Ubuntu 12.04, Apache/2.4.2, PHP 5.6.23-2+deb.sury.org~precise+1.
I've just installed this in a Vagrant box for testing. (That is, this isn't a prod server
with weird configs or a dev server wit cruft that's piled up over the years).

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70315


--
Edit this bug report at https://bugs.php.net/bug.php?id=70315&edit=1


Thread (17 messages)

« previous php.bugs (#202119) next »