Bug #79723 [PATCH]: sapi_cgi_read_post() ignores EOF

From: Date: Sun, 21 Jun 2020 18:59:06 +0000
Subject: Bug #79723 [PATCH]: sapi_cgi_read_post() ignores EOF
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227587@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79723&edit=1 ID: 79723 Patch added by: sam.revitch@protonmail.ch Reported by: sam dot revitch at protonmail dot ch Summary: sapi_cgi_read_post() ignores EOF Status: Open Type: Bug Package: FPM related Operating System: Linux PHP Version: 7.4.7 Block user comment: N Private report: N New Comment: The following patch has been added/updated: Patch Name: fcgi-read-eos.patch Revision: 1592765946 URL: https://bugs.php.net/patch-display.php?bug=79723&patch=fcgi-read-eos.patch&revision=1592765946 Previous Comments: ------------------------------------------------------------------------ [2020-06-21 18:58:52] sam dot revitch at protonmail dot ch Description: ------------ When FPM receives records: FCGI_BEGIN_REQUEST, FCGI_PARAMS, including CONTENT_LENGTH=x one or more nonempty FCGI_STDIN, with a total data length of y < x, and FCGI_STDIN end-of-stream (empty data) And the script reads php://input to the end, the read will hang until the socket is closed. This is because sapi_cgi_read_post() expects CONTENT_LENGTH bytes, and does not appear to honor the FastCGI end-of-stream indicator if it receives fewer. This is an edge case. I stumbled upon it using Apache, mod_proxy_fcgi, and mod_security, where mod_security aborts a request based on part of the body. It's certainly a bug that Apache doesn't close the FastCGI socket or send an abort record. However, PHP shouldn't be hanging indefinitely after receiving an end-of-stream. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79723&edit=1

« previous php.bugs (#227587) next »