Bug #69625 [Asn->Csd]: php-fpm return http 200 response on nginx without SCRIPT_FILENAME
| From: | bukka@php.net | Date: | Sun, 13 Dec 2020 18:40:21 +0000 |
| Subject: | Bug #69625 [Asn->Csd]: php-fpm return http 200 response on nginx without SCRIPT_FILENAME | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-231057@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69625&edit=1
ID: 69625
Updated by: bukka@php.net
Reported by: cfc4n at cnxct dot com
Summary: php-fpm return http 200 response on nginx without
SCRIPT_FILENAME
-Status: Assigned
+Status: Closed
Type: Bug
Package: FPM related
Operating System: linux
PHP Version: 5.6.9RC1
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of bukka
Revision: http://git.php.net/?p=php-src.git;a=commit;h=a221e17b41ad4c094908839593a0fd145b682f33
Log: Fix bug #69625: FPM returns 200 status on request without SCRIPT_FILENAME
Previous Comments:
------------------------------------------------------------------------
[2020-11-28 21:41:27] bukka@php.net
The following pull request has been associated:
Patch Name: FPM: Return 404 if the fcgi request is without SCRIPT_FILENAME
On GitHub: https://github.com/php/php-src/pull/6466
Patch: https://github.com/php/php-src/pull/6466.patch
------------------------------------------------------------------------
[2018-04-30 07:47:49] mr dot felixoid at gmail dot com
Here is PR for this problem https://github.com/php/php-src/pull/3227
------------------------------------------------------------------------
[2015-05-12 05:17:59] cfc4n at cnxct dot com
edit summary
------------------------------------------------------------------------
[2015-05-12 05:13:42] cfc4n at cnxct dot com
Description:
------------
In nginx config.conf file, configure info without fastcgi_param SCRIPT_FILENAME, Any PHP files are
returned blank response and http 200 status.
Because init_request_info function set default http response status 200, request_method is null in
fpm_main.c near line 985. And if SCRIPT_FILENAME was not set in CGI protocol,
SG(request_info).request_method \ SG(sapi_headers).http_response_code will not be reset .
The program will terminate at "if (!SG(request_info).request_method)" near line 1838 in
fpm_main.c ,
But http response status was 200 ,In fact it's a bug , The http response will be 404 , There is
comment in fpm_main.c near line 1846 "/* If path_translated is NULL, terminate here with a 404
*/" .
So, I think the code of SG(request_info).path_translated determine should be placed in front of
SG(request_info).request_method . Move line 1846-1855 into line 1835 .
more detail : http://www.cnxct.com/php-return-empty-result-on-nginx-without-script_filename/
Expected result:
----------------
return http response 404 and write php_error log whiteout SCRIPT_FILENAME
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69625&edit=1