Bug #80558 [Com]: Apache ErrorDocument subrequest fails horribly

From: Date: Mon, 28 Dec 2020 22:21:38 +0000
Subject: Bug #80558 [Com]: Apache ErrorDocument subrequest fails horribly
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231285@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80558&edit=1

 ID:                 80558
 Comment by:         problembug at speed dot 1s dot fr
 Reported by:        problembug at speed dot 1s dot fr
 Summary:            Apache ErrorDocument subrequest fails horribly
 Status:             Open
 Type:               Bug
 Package:            Apache related
 Operating System:   Linux
 PHP Version:        7.4.13
 Block user comment: N
 Private report:     N

 New Comment:

@rtrtrtrtrt at dfdfdfdf dot dfd

Yes certain and I think you've missed the point of the bug report that other bizarre PHP
behaviours are exhibited when switching from test 2 to 3. Again you seem to be guessing rather than
recreating and confirming. My examples are fully reproducible even without the closing tags (just
verified).  This is not a whitespace issue and I am not a novice PHP developer.

ob_start is not necessary to reproduce the behaviours so it is not included in my minimal viable
test case.

How do you explain messages about calls to ini_set?  Or that the include guard in require_once stops
functioning?


Previous Comments:
------------------------------------------------------------------------
[2020-12-28 21:21:46] rtrtrtrtrt at dfdfdfdf dot dfd

> seems like you're guessing rather than recreating the actual issue

and you are sure that no single include has a linebreak too much?
and you are sure that you start with ob_start() as first instruction of the first file?

i doubt!

"Headers already sent" is pretty always a user error

------------------------------------------------------------------------
[2020-12-28 21:00:57] problembug at speed dot 1s dot fr

@rtrtrtrtrt at dfdfdfdf dot dfd
There were no characters (including \n after the closing tags), I verified this before submitting
the bug report. It seems like you're guessing rather than recreating the actual issue.

------------------------------------------------------------------------
[2020-12-28 17:46:28] rtrtrtrtrt at dfdfdfdf dot dfd

just put ob_start() as first line of your error-script and/or remove linebreaks after ?> which is
the reason for *not* use ?> at the end of the file

for sure not a php bug

------------------------------------------------------------------------
[2020-12-28 16:44:10] problembug at speed dot 1s dot fr

Description:
------------
Reproducible on Amazon Linux, Slackware and others with various combinations of (recent) PHP and
Apache. When httpd.conf is configured with an ErrorDocument to a PHP script and an error is
deliberately introduced with a faulty header, the mere presence of a flush() changes the graceful
error handling (via a subrequest) in to a confusing and bizarre situation that introduces secondary
bugs.

These include:
o PHP no longer honours previous require_once include guard
o Apache not sending back any output to the client
o Misleading messages in the PHP error log about other modules
o Misleading messages in the PHP error log about ini_set (?) which is never used
o PHP error log messages repeated multiple times

The presence of a single flush() changes the graceful error handling ($test = 2) in to a confusing
mess ($test = 3) and introduces seemingly unrelated bugs.

Steps to reproduce:
1. Edit an Apache VirtualHost config in to include the following:
  ErrorDocument 500 /error.php
2. Place the 3 attached scripts in the VirtualHost's DocumentRoot:
  test.php error.php library.php
3. Restart Apache
4. Access https://somesite/test.php
5. Alter test.php to try $test = 2 and $test = 3
6. Observe all the unexpected and secondary problems the flush() introduces

Test script:
---------------
https://pastebin.com/MBQEEb5Q

Expected result:
----------------
Expected result for test 3 is same as test 2:

----

PHP error log:
No new entries.

----

$ curl -i https://somesite/test.php

HTTP/1.1 500 Internal Server Error
Date: Sun, 27 Dec 2020 14:05:47 GMT
Server: Apache
Content-Type: text/html; charset=UTF-8

I will deal with a 500 error and show a pretty error message

Actual result:
--------------
Actual result for test 3:

----

PHP error log:

[27-Dec-2020 13:49:41 UTC] PHP Warning:  flush(): Headers already sent. You cannot change the
session module's ini settings at this time in /www/test.php on line 22
[27-Dec-2020 13:49:41 UTC] PHP Warning:  flush(): Headers already sent. You cannot change the
session module's ini settings at this time in /www/test.php on line 22
[27-Dec-2020 13:49:41 UTC] PHP Warning:  flush(): Headers already sent. You cannot change the
session module's ini settings at this time in /www/test.php on line 22
[27-Dec-2020 13:49:41 UTC] PHP Warning:  flush(): Headers already sent. You cannot change the
session module's ini settings at this time in /www/test.php on line 22
[27-Dec-2020 13:49:41 UTC] PHP Fatal error:  Cannot redeclare foo() (previously declared in
/www/library.php:4) in /www/library.php on line 4

----

$ curl -i https://somesite/test.php

curl: (52) Empty reply from server


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80558&edit=1


Thread (7 messages)

« previous php.bugs (#231285) next »