Bug #72506 [Com]: idn_to_ascii for UTS #46 incorrect for long domain names
| From: | jules dot bernable at gmail dot com | Date: | Tue, 24 Jan 2023 12:05:14 +0000 |
| Subject: | Bug #72506 [Com]: idn_to_ascii for UTS #46 incorrect for long domain names | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-243552@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72506&edit=1
ID: 72506
Comment by: jules dot bernable at gmail dot com
Reported by: kulikovdn at gmail dot com
Summary: idn_to_ascii for UTS #46 incorrect for long domain
names
Status: Re-Opened
Type: Bug
Package: I18N and L10N related
Operating System: Linux Ubuntu 14.04
PHP Version: 7.1.0alpha1
Block user comment: N
Private report: N
New Comment:
The 255 octets limit is mentioned in several specifications:
RFC 1034 section 3.1 - Name space specifications and terminology:
> To simplify implementations, the total number of octets that represent
> a domain name (i.e., the sum of all label octets and label lengths) is
> limited to 255.
RFC 1036 section 2.3.4 - Size limits:
> Various objects and parameters in the DNS have size limits.
> They are listed below.
> Some could be easily changed, others are more fundamental.
> labels 63 octets or less
> names 255 octets or less
> TTL positive values of a signed 32 bit number.
> UDP messages 512 octets or less
RFC 2181 section 11 - Name syntax:
> The DNS itself places only one restriction on the particular labels
> that can be used to identify resource records.
> That one restriction relates to the length of the label and the full name.
> The length of any one label is limited to between 1 and 63 octets.
> A full domain name is limited to 255 octets (including the separators)
So it seems that the behaviour of the IDNA functions is correct WRT the aforementioned
specifications.
Previous Comments:
------------------------------------------------------------------------
[2016-11-22 13:02:14] cmb@php.net
Related To: Bug #73577
------------------------------------------------------------------------
[2016-11-22 13:00:08] cmb@php.net
This has been inadvertantly closed â reopening.
------------------------------------------------------------------------
[2016-10-17 10:11:22] bwoebi@php.net
Automatic comment on behalf of cmb
Revision: http://git.php.net/?p=php-src.git;a=commit;h=76e249d31c51d0b4f8f11507c550ca1eec1dd38a
Log: Partially fix #72506: idn_to_ascii for UTS #46 incorrect for long domain names
------------------------------------------------------------------------
[2016-07-12 12:57:07] cmb@php.net
Automatic comment on behalf of cmb
Revision: http://git.php.net/?p=php-src.git;a=commit;h=76e249d31c51d0b4f8f11507c550ca1eec1dd38a
Log: Partially fix #72506: idn_to_ascii for UTS #46 incorrect for long domain names
------------------------------------------------------------------------
[2016-07-11 23:18:04] cmb@php.net
Indeed, idn_to_ascii() appears to be overly restrictive. If the
resulting domain is 255 bytes long, it raises an error[1], if it
is longer, it returns FALSE and doesn't fill $idna_info[2]. This
inconsistency is definitely a bug.
Not filling $idna_info when the resulting domain is longer than
254 bytes is also a bug according to the documentation[3] which
states:
| In that case, it will be filled with an array with the keys
| 'result', the possibly illegal result of the transformation, [â¦]
The issue here is that we have to allocate a buffer in advance
(i.e. before the length of the resulting domain is known)[4]. Of
course, it would be possible to allocate a larger buffer, but that
might still not be big enough, and appears to be useless anyway,
because the domain name would be invalid. Therefore I suggest to
set $idna_info['result'] to NULL for excessive resulting domains,
and to only do this as of PHP 7.1, due to the (minor) BC break.
For current versions, the documentation should be fixed.
[1] <https://github.com/php/php-src/blob/php-5.6.23/ext/intl/idn/idn.c#L167-L169>
[2] <https://github.com/php/php-src/blob/php-5.6.23/ext/intl/idn/idn.c#L161-L166>
[3] <http://php.net/manual/en/function.idn-to-ascii.php>
[4] <https://github.com/php/php-src/blob/php-5.6.23/ext/intl/idn/idn.c#L142-L143>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72506
--
Edit this bug report at https://bugs.php.net/bug.php?id=72506&edit=1