Bug #70470 [Ver->Csd]: Built-in server truncates headers spanning over TCP packets

From: Date: Tue, 05 Sep 2017 14:25:52 +0000
Subject: Bug #70470 [Ver->Csd]: Built-in server truncates headers spanning over TCP packets
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210958@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70470&edit=1 ID: 70470 Updated by: nikic@php.net Reported by: bwoebi@php.net Summary: Built-in server truncates headers spanning over TCP packets -Status: Verified +Status: Closed Type: Bug Package: Built-in web server Operating System: Irrelevant PHP Version: 5.6.13 Block user comment: N Private report: N New Comment: Automatic comment on behalf of boukevanderbijl@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=cd9d90f4d41c87494dee8ee72c7a48951213296b Log: Fixed bug #70470 Previous Comments: ------------------------------------------------------------------------ [2017-09-04 15:08:46] bouke at shopify dot com Hey y'all I've made a patch that fixes this issue: https://github.com/php/php-src/pull/2736 ------------------------------------------------------------------------ [2016-01-29 02:22:35] cmstlist at gmail dot com Just wanted to add, I am experiencing this while trying to get Google's Identity Framework ("Gitkit") Quick Start for PHP working on my local computer for a school project. https://developers.google.com/identity/toolkit/web/quickstart/php I have a test site set up to accept Facebook or Google logins. My code is not significantly modified from theirs aside from removing the "password" login option from the config array. When logged in with my Facebook account, the Gitkit client-side JS library produces a 1015-character token that it stores in a cookie. Sporadically PHP truncates the token down to 310 characters or so, and as a result Google's OAuth2 library throws an exception (complaining the token does not have enough segments). Within a few refreshes it works again. When logged in with my Google account the token is only about 896 characters long. This rarely gets truncated and thus rarely throws the same exception. ------------------------------------------------------------------------ [2015-09-11 14:35:26] bwoebi@php.net The only solution is a different buffer… you may want to use a char[PHP_HTTP_MAX_HEADER_SIZE] allocated along with the client context, then copy in and out when you need to return. I don't really see a better way here... check state at the end, copy if necessary… then on header value/name use that buffer then… ------------------------------------------------------------------------ [2015-09-11 14:35:25] bwoebi@php.net The only solution is a different buffer… you may want to use a char[PHP_HTTP_MAX_HEADER_SIZE] allocated along with the client context, then copy in and out when you need to return. I don't really see a better way here... check state at the end, copy if necessary… then on header value/name use that buffer then… ------------------------------------------------------------------------ [2015-09-11 05:51:17] laruence@php.net actually, not only header_value, but also header name, I committed a test script here: https://github.com/php/php-src/commit/37d814b84cff3678a2e1d56ea9d3ba3c35082e13 however, I don't see a good fix in the current implementation now... :< thanks ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70470 -- Edit this bug report at https://bugs.php.net/bug.php?id=70470&edit=1

« previous php.bugs (#210958) next »