Bug #73037 [Opn->Asn]: SoapServer reports Bad Request when gzipped

From: Date: Fri, 09 Sep 2016 23:06:24 +0000
Subject: Bug #73037 [Opn->Asn]: SoapServer reports Bad Request when gzipped
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203933@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73037&edit=1

 ID:                 73037
 Updated by:         bwoebi@php.net
 Reported by:        maggus dot staab at googlemail dot com
 Summary:            SoapServer reports Bad Request when gzipped
-Status:             Open
+Status:             Assigned
 Type:               Bug
 Package:            SOAP related
 Operating System:   Ubuntu14LTS
 PHP Version:        5.6.25
-Assigned To:        
+Assigned To:        ab
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2016-09-09 17:53:43] bwoebi@php.net

I had looked at the issue and it's not related to any extension (only zlib, soap and libxml
code is ever called).

There's something fishy when _php_stream_read() is called recursively though.

Thus simple code like:

class simple_filter extends php_user_filter {
    function filter($in, $out, &$consumed, $closing) {
        while ($bucket = stream_bucket_make_writeable($in)) {
            $consumed += $bucket->datalen;
            stream_bucket_append($out, $bucket);
        }
        return PSFS_PASS_ON;
    }
}
stream_filter_register("simple", "simple_filter");
file_get_contents("php://filter/read=simple/resource=http://google.com");

is also failing in PHP 7. (works flawlessly with PHP 5.)

------------------------------------------------------------------------
[2016-09-08 22:56:15] ab@php.net

Thanks for the report. Is the behavior same without Opcache and Blackfire? Ideally, with anything
except soap and gzip excluded.

Thanks.

------------------------------------------------------------------------
[2016-09-07 08:03:08] maggus dot staab at googlemail dot com

Description:
------------
SoapServer->handle() reports a bad-request when issuing a request with gzip.
triggering the very same request without gzip encoding works as expected.
SoapServer seems not to be able to read and parse the posted XML body.
the error is reproducible on php 5.6.23 and 7.0.10.

the testscript works (both in gzip and non-gzip) on php 5.4.45 (on ubuntu12 lts)


here some detail of the involved php versions:

mstaab@mst14:~$ php -v
PHP 7.0.10-2+deb.sury.org~trusty+1 (cli) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
    with Zend OPcache v7.0.10-2+deb.sury.org~trusty+1, Copyright (c) 1999-2016, by Zend Technologies
    with blackfire v1.12.0, https://blackfire.io, by Blackfireio
Inc.

mstaab@mst14:~$ php5 -v
PHP 5.6.23-1+deprecated+dontuse+deb.sury.org~trusty+1 (cli)
Copyright (c) 1997-2016 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies
    with Zend OPcache v7.0.6-dev, Copyright (c) 1999-2016, by Zend Technologies
    with Zend Debugger v8.0.0, Copyright (c) 1999-2014, by Zend Technologies
    with blackfire v1.12.0, https://blackfire.io, by Blackfireio
Inc.

mstaab@vStaab12:~$ php -v
PHP 5.4.45-3+deb.sury.org~precise+1 (cli) (built: Jan  7 2016 15:32:17)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.4.0, Copyright (c) 1998-2014 Zend Technologies
    with Zend Debugger v6.0.0, Copyright (c) 1999-2013, by Zend Technologies
    with blackfire v1.11.1, https://blackfire.io, by Blackfireio
Inc.


Test script:
---------------
mstaab@mst14:~$ cat server.php
<?php

$s = new SoapServer(NULL, array('uri' => 'http://localhost/server.php'));
$s->setObject(new stdclass());
$s->handle();


mstaab@mst14:~$ cat postgz.sh
#!/bin/bash
curl \
    -H "Content-Type: application/soap+xml; charset=UTF-8" \
    -H "Accept: application/soap+xml, application/dime, multipart/related, text/*" \
    -H 'SOAPAction: "urn:adressen#adressen#SetAda"' \
    -H 'Content-Encoding: gzip' \
--data-binary @<(cat cd_catalog.xml | gzip) \
    -X POST http://localhost:8000/server.php


mstaab@mst14:~$ cat post.sh
#!/bin/bash
curl \
    -H "Content-Type: application/soap+xml; charset=UTF-8" \
    -H "Accept: application/soap+xml, application/dime, multipart/related, text/*" \
    -H 'SOAPAction: "urn:adressen#adressen#SetAda"' \
--data-binary @<(cat cd_catalog.xml) \
    -X POST http://localhost:8000/server.php

cd_catalog.xml can be found at https://gist.github.com/staabm/fc96933585c11fe277b658c62c877345


you just need to start the builtin-webserver using php -S localhost:8000 and trigger post.sh respec.
postgz.sh


Expected result:
----------------
mstaab@vStaab12:~$ ./post.sh
<?xml version="1.0" encoding="UTF-8"?>
<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope"><env:Body><env:Fault><env:Code><env:Value>env:Receiver</env:Value></env:Code><env:Reason><env:Text>Function
'CATALOG't
exist</env:Text></env:Reason></env:Fault></env:Body></env:Envelope>

mstaab@vStaab12:~$ ./postgz.sh
<?xml version="1.0" encoding="UTF-8"?>
<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope"><env:Body><env:Fault><env:Code><env:Value>env:Receiver</env:Value></env:Code><env:Reason><env:Text>Function
'CATALOG't
exist</env:Text></env:Reason></env:Fault></env:Body></env:Envelope>


Actual result:
--------------
mstaab@mst14:~$ ./post.sh
<?xml version="1.0" encoding="UTF-8"?>
<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope"><env:Body><env:Fault><env:Code><env:Value>env:Receiver</env:Value></env:Code><env:Reason><env:Text>Function
'CATALOG't
exist</env:Text></env:Reason></env:Fault></env:Body></env:Envelope>

mstaab@mst14:~$ ./postgz.sh
<?xml version="1.0" encoding="UTF-8"?>
<SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"><SOAP-ENV:Body><SOAP-ENV:Fault><faultcode>SOAP-ENV:Client</faultcode><faultstring>Bad
Request</faultstring></SOAP-ENV:Fault></SOAP-ENV:Body></SOAP-ENV:Envelope>



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73037&edit=1


Thread (21 messages)

« previous php.bugs (#203933) next »