Bug #77780 [NEW]: "Headers already sent..." when previous connection was aborted
| From: | mp at webfactory dot de | Date: | Fri, 22 Mar 2019 10:09:19 +0000 |
| Subject: | Bug #77780 [NEW]: "Headers already sent..." when previous connection was aborted | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-220124@lists.php.net to get a copy of this message | ||
From: mp at webfactory dot de
Operating system: Ubuntu 18.04.2 LTS
PHP version: 7.2.16
Package: Session related
Bug Type: Bug
Bug description:"Headers already sent..." when previous connection was aborted
Description:
------------
I am running Apache and forwarding PHP requests to PHP-FPM.
In the Apache error logfile as well as in the PHP-FPM log, there are
spurious messages as follows:
AH01071: Got error 'PHP message: PHP Warning: Unknown: Headers already
sent. You cannot change the session module's ini settings at this time
in Unknown on line 0\nPHP message: PHP Warning: Unknown: Headers
already sent. You cannot change the session module's ini settings at
this time in Unknown on line 0\n'
I found out that this happens when a PHP-FPM process serves a request
and the connection is aborted by the client. Then the *next* request
served by this PHP-FPM process will get the above error message.
Probably relevant information:
- I am forwarding per-vhost configuration settings to PHP-FPM. In
Apache, this can be done as follows:
ProxyFCGISetEnvIf "true" PHP_VALUE
"session.save_path=\"/some/path/per/vhost\" \n
session.cookie_secure=\"1\" \n"
- ignore_user_abort is set to "Off", the default setting.
My guess is that there is some per-connection flag that tracks whether
the headers have already been sent, and that this flag is not correctly
reset when the script is aborted by a connection reset. Not sure if this
is related to PHP-FPM, the SAPI or even a more general problem.
Exact PHP version is PHP 7.2.15-0ubuntu0.18.04.1, the one currently
provided by Ubuntu 18.04.2 LTS.
Test script:
---------------
1. Set up an Apache vhost to use PHP-FPM. Include the following
configuration setting to apply PHP settings per vhost, i. e. settings
that PHP-FPM has to apply for every single request handled.
ProxyFCGISetEnvIf "true" PHP_VALUE
"session.save_path=\"/some/path/per/vhost\" \n
session.cookie_secure=\"1\" \n"
2. To make sure all requests hit the same PHP-FPM worker process,
configure PHP-FPM with pm=static and pm.max_children=1.
3. Make the following scripts available on the webserver:
<?php # slow.php
print str_repeat('asdfghjkl', 150000);
print "\n";
print "done";
---
<?php # noop.php
// empty script
---
4. Run the following script to request slow.php, abort the connection,
and run noop.php afterwards:
<?php
$fp = fopen('http://url/to/slow.php',
'r');
fread($fp, 1024);
fclose($fp);
file_get_contents('http://url/to/noop.php');
---
5. Observe that the content-length logged by Apache for the slow.php
requests is below the 1.3MB actually emitted by the script, but (for me)
always larger than the 1024 bytes read by test.php. In practice, values
fluctuacte around 100KB.
6. The error message "PHP message: PHP Warning: Unknown: Headers
already sent. You cannot change the session module's ini settings at
this time in Unknown on line 0" shows up in server and/or PHP-FPM
logfiles.
7. Re-configure PHP-FPM to have ignore_user_abort = On.
8. Repeat steps 4-5. The error message from 6. does not appear this
time.
Expected result:
----------------
No error message should occur and the session configuration should be
applied in either case.
--
Edit bug report at https://bugs.php.net/bug.php?id=77780&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77780&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77780&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77780&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=77780&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=77780&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=77780&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=77780&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=77780&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=77780&r=support
Expected behavior: https://bugs.php.net/fix.php?id=77780&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=77780&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=77780&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=77780&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77780&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=77780&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=77780&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=77780&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77780&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=77780&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=77780&r=mysqlcfg