[php-src] Issue #24115: [CLI server] Apply a size limit to chunked request trailers

From: Date: Sun, 04 Oct 2026 11:55:04 +0000
Subject: [php-src] Issue #24115: [CLI server] Apply a size limit to chunked request trailers
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-252898@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/24115 Author: bupt-Yy-young ### Description In the php-src master snapshot 63b0af4a5c400d93510dca7aa998769609fdc26c (2026-10-04), the built-in CLI server's HTTP header-size accounting appears not to include chunked-request trailers. The parser's PARSING_HEADER macro excludes states while F_TRAILING is set (sapi/cli/php_http_parser.c:204). After the zero-size chunk sets that flag (:1472-1474), trailer bytes therefore bypass the PHP_HTTP_MAX_HEADER_SIZE counter/check (:314-318). The CLI server still accumulates trailer field/value bytes into persistent strings and its per-client header tables (sapi/cli/php_cli_server.c:1705-1764), with no corresponding trailer-size limit found. These persistent allocations remain associated with the connection until its request/client teardown and are not governed by memory_limit. A client can send a chunked request, start a large trailer field after the zero chunk, and continue streaming trailer bytes without completing the trailer block. This can grow the php -S process memory for as long as the connection remains open. The ordinary header cap and post_max_size do not appear to cover this trailer path. ### Expected behavior Apply a total byte/count limit to trailers as well as regular headers, and close/reject the request once it is exceeded. ### Reproduction outline Start php -S with a trivial document root. Open a raw TCP connection and send a chunked HTTP/1.1 request whose body ends with 0\r\nX-Fill: , then stream a large value without completing the trailer section (\r\n\r\n). Observe whether the server process's RSS grows beyond the normal header-size limit while the connection remains open. I have traced this statically in the referenced source; I have not run this outline against a compiled build. This is reported as a robustness/resource-management bug in the development server, not as a claim about production SAPI deployments.

« previous php.bugs (#252898) next »