Bug #80849 [Opn->Ver]: HTTP Status header truncation
Edit report at https://bugs.php.net/bug.php?id=80849&edit=1
ID: 80849
Updated by: cmb@php.net
Reported by: ben dot bidner at automattic dot com
Summary: HTTP Status header truncation
-Status: Open
+Status: Verified
Type: Bug
-Package: FPM related
+Package: CGI/CLI related
PHP Version: 8.0.3
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2021-03-28 22:35:41] avinash dot roshan dot dsilva at gmail dot com
would the following change do the trick?
```
len = slprintf(buf, sizeof(buf)+2, "Status:%s\r\n",s);
```
------------------------------------------------------------------------
[2021-03-09 18:36:51] ben dot bidner at automattic dot com
Description:
------------
sapi_cgi_send_headers() (in both sapi/fpm/fpm/fpm_main.c and
sapi/cgi/cgi_main.c) will truncate HTTP Status headers larger than
SAPI_CGI_MAX_HEADER_LENGTH in the following cases, potentially causing the trailing CR
LF to be stripped.
len = slprintf(buf, SAPI_CGI_MAX_HEADER_LENGTH, "%s\r\n",
SG(sapi_headers).http_status_line);
len = slprintf(buf, sizeof(buf), "Status:%s\r\n", s);
len = slprintf(buf, sizeof(buf), "Status: %d %s\r\n",
SG(sapi_headers).http_response_code, err->str);
len = slprintf(buf, sizeof(buf), "Status: %d\r\n",
SG(sapi_headers).http_response_code);
Removing the CR LFs and explicitly sending them after the header is sent (as per other headers in
the code below this) should be sufficient to fix?
Test script:
---------------
<?php
header( 'HTTP/1.1 201 ' . str_repeat( 'A', 1011 ), true );
exit;
Actual result:
--------------
The example above will return the following headers
HTTP/1.1 201 AAA...AAAContent-type: text/html; charset=UTF-8
Server: nginx
Date: Tue, 09 Mar 2021 18:06:36 GMT
Connection: keep-alive
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80849&edit=1
Thread (5 messages)