Bug #79102 [NEW]: php-cgi.exe exits when processing SabreDAV requests

From: Date: Sat, 11 Jan 2020 18:33:41 +0000
Subject: Bug #79102 [NEW]: php-cgi.exe exits when processing SabreDAV requests
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224846@lists.php.net to get a copy of this message
From:             mbiebl at messageconcept dot com
Operating system: Windows Server 2016
PHP version:      7.3.13
Package:          IIS related
Bug Type:         Bug
Bug description:php-cgi.exe exits when processing SabreDAV requests

Description:
------------
Hello,

we are using SabreDAV http://sabre.io/ under Windows/IIS and run into
an
interesting problem.
Whenever a request with request data is sent to SabreDAV, the
php-cgi.exe process exits.
PHP is version 7.3.13, we use IIS with fastcgi.
https://mynebula.net/index.php/s/b3fAYyYei6G5tjA
demonstrates the
problem.

Unfortunately, it's not trivial to reduce the issue to a short
reproducer script.
If you want to reproduce the issue, the following steps are necessary

1/ Download the zip file from
https://mynebula.net/index.php/s/3JsoEfbXcpgCiet
2/ Setup an IIS website pointing at the directory where you unpackage
the zipfile, I used port 9090 as binding
3/ Make sure the site is configured as in the web.config, you will need
to adjust the path to the php binary
4/ run curl as in test.sh

What we figured out so far is, that the problem only happens, if curl is
sending request data. We can work around the problem by adding a line
 file_get_contents('php://input');
in server.php before the 
 $server->exec(); 
line

I tried to run xdebug with a function trace, trying to figure out what's
going on, but unfortunately I'm kinda stuck at this point.
It's not clear to me, we php-cgi.exe simply exits after processing the
request.

Test script:
---------------
composer.json
==============
{
	"require" : {
		"sabre/dav" : "4.0.*" 
	}
}

server.php
==========
<?php

/*

Addressbook/CardDAV server example

This server features CardDAV support

*/

#xdebug_start_trace();

function exception_error_handler($errno, $errstr, $errfile, $errline )
{
    throw new \ErrorException($errstr, 0, $errno, $errfile, $errline);
}
set_error_handler('exception_error_handler');

// settings
date_default_timezone_set('Europe/Berlin');

// Make sure this setting is turned on and reflect the root url for your
WebDAV server.
// This can be for example the root / or a complete path to your server
script
$baseUri = '/';

/* Database */
$pdo = new PDO('sqlite:data/db.sqlite');
$pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);

// Autoloader
require_once 'vendor/autoload.php';

// Backends
$authBackend = new Sabre\DAV\Auth\Backend\PDO($pdo);
$principalBackend = new Sabre\DAVACL\PrincipalBackend\PDO($pdo);
$carddavBackend = new Sabre\CardDAV\Backend\PDO($pdo);

// Setting up the directory tree //
$nodes = [
    new Sabre\DAVACL\PrincipalCollection($principalBackend),
    new Sabre\CardDAV\AddressBookRoot($principalBackend,
$carddavBackend),
];

// The object tree needs in turn to be passed to the server class
$server = new Sabre\DAV\Server($nodes);
$server->setBaseUri($baseUri);

// Plugins
$server->addPlugin(new Sabre\DAV\Auth\Plugin($authBackend));
$server->addPlugin(new Sabre\DAV\Browser\Plugin());
$server->addPlugin(new Sabre\CardDAV\Plugin());
$server->addPlugin(new Sabre\DAV\Sync\Plugin());
// Hide nodes that the user does not have access to
$aclPlugin = new \Sabre\DAVACL\Plugin();
$aclPlugin->hideNodesFromListings = true;
$aclPlugin->allowUnauthenticatedAccess = false;
$server->addPlugin($aclPlugin);

// And off we go!
$server->start();


web.config
==========
<?xml version="1.0" encoding="UTF-8"?>
<configuration>
    <system.webServer>
        <rewrite>
            <rules>
                <rule name="Rewrite to server.php">
                    <match url=".*" />
                    <action type="Rewrite" url="server.php" />
                </rule>
            </rules>
        </rewrite>
        <security>
            <requestFiltering>
                <verbs>
                    <add verb="PROPFIND" allowed="true" />
                </verbs>
            </requestFiltering>
        </security>
        <handlers>
            <remove name="WebDAV" />
            <add name="PHP7_via_FastCGI" path="*.php" verb="OPTIONS,
GET, HEAD, POST, PUT, DELETE, TRACE, COPY, MOVE, MKCOL, PROPFIND,
PROPPATCH, LOCK, UNLOCK, REPORT, ACL" modules="FastCgiModule"
scriptProcessor="C:\Program Files (x86)\PHP\v7.3\php-cgi.exe"
resourceType="Either" requireAccess="Script" />
        </handlers>
        <defaultDocument enabled="false">
            <files>
                <remove value="index.php" />
                <remove value="default.aspx" />
                <add value="server.php" />
            </files>
        </defaultDocument>
        <modules>
            <remove name="WebDAVModule" />
        </modules>
    </system.webServer>
</configuration>

test.sh
=======
user=admin
pass=admin

for i in seq 1 5; do
curl -H "Accept: text/xml" -H "Content-Type: text/xml; charset=utf-8" -X
PROPFIND http://localhost:9090/ \
	--data '<?xml version="1.0" encoding="utf-8"?><D:propfind
xmlns:D="DAV:"><D:prop><addressbook-home-set
xmlns="urn:ietf:params:xml:ns:carddav" /></D:prop></D:propfind>'
done



-- 
Edit bug report at https://bugs.php.net/bug.php?id=79102&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=79102&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=79102&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=79102&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=79102&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=79102&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=79102&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=79102&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=79102&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=79102&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=79102&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79102&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=79102&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=79102&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=79102&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=79102&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=79102&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=79102&r=mysqlcfg


Thread (12 messages)

« previous php.bugs (#224846) next »