Bug #81516 [NEW]: Curl used with CURLOPT_WRITEFUNCTION rarely corrupts the response

From: Date: Fri, 08 Oct 2021 17:52:08 +0000
Subject: Bug #81516 [NEW]: Curl used with CURLOPT_WRITEFUNCTION rarely corrupts the response
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237110@lists.php.net to get a copy of this message
From:             roland at nextendweb dot com
Operating system: 
PHP version:      7.4.24
Package:          Streams related
Bug Type:         Bug
Bug description:Curl used with CURLOPT_WRITEFUNCTION rarely corrupts the response

Description:
------------
This issue happened through WordPress update system during plugin
update. Our update url points to our private server and serving a zip
file. We had tens of thousands updates for this very same file and there
were only 2 sites which had this issue, so I think it is not related how
we serve the file.

The error is md5_mismatch: The checksum of the file
(4a3b968a44c585a2883e687d61c251fb) does not match the expected checksum
value (231732259d67fe83ed6fc02d7ad9be57).

I started to debug this issue, I had the original zip file and the
corrupted one which WordPress downloaded. I diffed the files and at some
point it seems like some part is missing in the corrupted file. Like the
stream lost a piece from the buffer. And it happens all the time on
those servers.

https://i.imgur.com/Nx0SKeK.png

Curl transport handled this download, so I head over to
/wp-includes/Requests/Transport/cURL.php:
https://github.com/WordPress/WordPress/blob/master/wp-includes/Requests/Transport/cURL.php

And when I removed CURLOPT_BUFFERSIZE or changed anything else
(Requests::BUFFER_SIZE+1, Requests::BUFFER_SIZE-1), download_url
function started to behave as it should and the file was not corrupted
anymore.
<?php
curl_setopt($this->handle, CURLOPT_BUFFERSIZE, Requests::BUFFER_SIZE);


Requests::BUFFER_SIZE value is 1160 in WordPress.

Exactly one 1160 bytes block is missing in the middle of the file, which
is the value of Requests::BUFFER_SIZE.

https://i.imgur.com/KoWkzco.png


Both site had the following configuration:
WordPress 5.8.1
PHP 7.4.24
Curl 7.71.0


-- 
Edit bug report at https://bugs.php.net/bug.php?id=81516&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=81516&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=81516&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=81516&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=81516&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=81516&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=81516&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=81516&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=81516&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=81516&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=81516&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=81516&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=81516&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=81516&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=81516&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=81516&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=81516&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=81516&r=mysqlcfg


Thread (14 messages)

« previous php.bugs (#237110) next »