Bug #69625 [Asn->Csd]: php-fpm return http 200 response on nginx without SCRIPT_FILENAME

From: Date: Sun, 13 Dec 2020 18:40:21 +0000
Subject: Bug #69625 [Asn->Csd]: php-fpm return http 200 response on nginx without SCRIPT_FILENAME
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231057@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69625&edit=1 ID: 69625 Updated by: bukka@php.net Reported by: cfc4n at cnxct dot com Summary: php-fpm return http 200 response on nginx without SCRIPT_FILENAME -Status: Assigned +Status: Closed Type: Bug Package: FPM related Operating System: linux PHP Version: 5.6.9RC1 Assigned To: bukka Block user comment: N Private report: N New Comment: Automatic comment on behalf of bukka Revision: http://git.php.net/?p=php-src.git;a=commit;h=a221e17b41ad4c094908839593a0fd145b682f33 Log: Fix bug #69625: FPM returns 200 status on request without SCRIPT_FILENAME Previous Comments: ------------------------------------------------------------------------ [2020-11-28 21:41:27] bukka@php.net The following pull request has been associated: Patch Name: FPM: Return 404 if the fcgi request is without SCRIPT_FILENAME On GitHub: https://github.com/php/php-src/pull/6466 Patch: https://github.com/php/php-src/pull/6466.patch ------------------------------------------------------------------------ [2018-04-30 07:47:49] mr dot felixoid at gmail dot com Here is PR for this problem https://github.com/php/php-src/pull/3227 ------------------------------------------------------------------------ [2015-05-12 05:17:59] cfc4n at cnxct dot com edit summary ------------------------------------------------------------------------ [2015-05-12 05:13:42] cfc4n at cnxct dot com Description: ------------ In nginx config.conf file, configure info without fastcgi_param SCRIPT_FILENAME, Any PHP files are returned blank response and http 200 status. Because init_request_info function set default http response status 200, request_method is null in fpm_main.c near line 985. And if SCRIPT_FILENAME was not set in CGI protocol, SG(request_info).request_method \ SG(sapi_headers).http_response_code will not be reset . The program will terminate at "if (!SG(request_info).request_method)" near line 1838 in fpm_main.c , But http response status was 200 ,In fact it's a bug , The http response will be 404 , There is comment in fpm_main.c near line 1846 "/* If path_translated is NULL, terminate here with a 404 */" . So, I think the code of SG(request_info).path_translated determine should be placed in front of SG(request_info).request_method . Move line 1846-1855 into line 1835 . more detail : http://www.cnxct.com/php-return-empty-result-on-nginx-without-script_filename/ Expected result: ---------------- return http response 404 and write php_error log whiteout SCRIPT_FILENAME ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69625&edit=1

« previous php.bugs (#231057) next »