Bug #72506 [Com]: idn_to_ascii for UTS #46 incorrect for long domain names

From: Date: Tue, 24 Jan 2023 12:05:14 +0000
Subject: Bug #72506 [Com]: idn_to_ascii for UTS #46 incorrect for long domain names
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243552@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72506&edit=1 ID: 72506 Comment by: jules dot bernable at gmail dot com Reported by: kulikovdn at gmail dot com Summary: idn_to_ascii for UTS #46 incorrect for long domain names Status: Re-Opened Type: Bug Package: I18N and L10N related Operating System: Linux Ubuntu 14.04 PHP Version: 7.1.0alpha1 Block user comment: N Private report: N New Comment: The 255 octets limit is mentioned in several specifications: RFC 1034 section 3.1 - Name space specifications and terminology: > To simplify implementations, the total number of octets that represent > a domain name (i.e., the sum of all label octets and label lengths) is > limited to 255. RFC 1036 section 2.3.4 - Size limits: > Various objects and parameters in the DNS have size limits. > They are listed below. > Some could be easily changed, others are more fundamental. > labels 63 octets or less > names 255 octets or less > TTL positive values of a signed 32 bit number. > UDP messages 512 octets or less RFC 2181 section 11 - Name syntax: > The DNS itself places only one restriction on the particular labels > that can be used to identify resource records. > That one restriction relates to the length of the label and the full name. > The length of any one label is limited to between 1 and 63 octets. > A full domain name is limited to 255 octets (including the separators) So it seems that the behaviour of the IDNA functions is correct WRT the aforementioned specifications. Previous Comments: ------------------------------------------------------------------------ [2016-11-22 13:02:14] cmb@php.net Related To: Bug #73577 ------------------------------------------------------------------------ [2016-11-22 13:00:08] cmb@php.net This has been inadvertantly closed – reopening. ------------------------------------------------------------------------ [2016-10-17 10:11:22] bwoebi@php.net Automatic comment on behalf of cmb Revision: http://git.php.net/?p=php-src.git;a=commit;h=76e249d31c51d0b4f8f11507c550ca1eec1dd38a Log: Partially fix #72506: idn_to_ascii for UTS #46 incorrect for long domain names ------------------------------------------------------------------------ [2016-07-12 12:57:07] cmb@php.net Automatic comment on behalf of cmb Revision: http://git.php.net/?p=php-src.git;a=commit;h=76e249d31c51d0b4f8f11507c550ca1eec1dd38a Log: Partially fix #72506: idn_to_ascii for UTS #46 incorrect for long domain names ------------------------------------------------------------------------ [2016-07-11 23:18:04] cmb@php.net Indeed, idn_to_ascii() appears to be overly restrictive. If the resulting domain is 255 bytes long, it raises an error[1], if it is longer, it returns FALSE and doesn't fill $idna_info[2]. This inconsistency is definitely a bug. Not filling $idna_info when the resulting domain is longer than 254 bytes is also a bug according to the documentation[3] which states: | In that case, it will be filled with an array with the keys | 'result', the possibly illegal result of the transformation, […] The issue here is that we have to allocate a buffer in advance (i.e. before the length of the resulting domain is known)[4]. Of course, it would be possible to allocate a larger buffer, but that might still not be big enough, and appears to be useless anyway, because the domain name would be invalid. Therefore I suggest to set $idna_info['result'] to NULL for excessive resulting domains, and to only do this as of PHP 7.1, due to the (minor) BC break. For current versions, the documentation should be fixed. [1] <https://github.com/php/php-src/blob/php-5.6.23/ext/intl/idn/idn.c#L167-L169> [2] <https://github.com/php/php-src/blob/php-5.6.23/ext/intl/idn/idn.c#L161-L166> [3] <http://php.net/manual/en/function.idn-to-ascii.php> [4] <https://github.com/php/php-src/blob/php-5.6.23/ext/intl/idn/idn.c#L142-L143> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72506 -- Edit this bug report at https://bugs.php.net/bug.php?id=72506&edit=1

« previous php.bugs (#243552) next »