Bug #73936 [Opn]: Certain special header() calls wrongly prevent connection from closing

From: Date: Thu, 04 Nov 2021 14:03:49 +0000
Subject: Bug #73936 [Opn]: Certain special header() calls wrongly prevent connection from closing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237549@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73936&edit=1

 ID:                 73936
 Updated by:         cmb@php.net
 Reported by:        markamery at btinternet dot com
 Summary:            Certain special header() calls wrongly prevent
                     connection from closing
 Status:             Open
 Type:               Bug
 Package:            Apache2 related
 Operating System:   Ubuntu
 PHP Version:        Irrelevant
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

> Unless Connection: keep-alive is specified in the request, the
> connection should close once the PHP script finishes.

For HTTP/1.1 requests, keep-alive is the default.  Only HTTP/1.0
defaults to close.[1]

> header('http/1.1 200 OK')

This is not valid according to RFC 7230, since the HTTP-name needs
to be upper case[2].

> http_response_code(200);

I tentatively agree that this should behave identically to
header('HTTP/1.1 200 OK').  I'll' have a closer look.

[1] <https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Connection>
[2] <https://datatracker.ietf.org/doc/html/rfc7230#appendix-B>


Previous Comments:
------------------------------------------------------------------------
[2017-01-14 18:38:54] markamery at btinternet dot com

Description:
------------
Running under mod_php, calling

    header('HTTP/1.1 200 OK');

seems to prevent the connection from being closed once the PHP script finishes. This can be
demonstrated by, for instance, hitting the script with ab (the Apache benchmark tool), which (unlike
most HTTP clients, including browsers) only considers a request to have finished once the connection
is closed, rather than when Content-Length bytes have been received. http://stackoverflow.com/q/34367115/1709587
describes this case in more detail.

Bizarrely,

    header('http/1.1 200 OK');

does not have the same effect, despite producing a character-for-character identical HTTP response
(as can be observed with curl -i --raw).

Test script:
---------------
<?php

header('HTTP/1.1 200 OK');


Expected result:
----------------
Unless Connection: keep-alive is specified in the request, the connection should close
once the PHP script finishes. In particular, the behaviour should be identical to other calls with
the same meaning, like

    <?php
    
        http_response_code(200);

or

    <?php

        header('http/1.1 200 OK')

Actual result:
--------------
The connection does not close, and the alternate scripts suggested above have different behaviours
to the test script.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73936&edit=1


Thread (6 messages)

« previous php.bugs (#237549) next »