[php-src] Issue #24115: [CLI server] Apply a size limit to chunked request trailers
| From: | bupt-Yy-young | Date: | Sun, 04 Oct 2026 11:55:04 +0000 |
| Subject: | [php-src] Issue #24115: [CLI server] Apply a size limit to chunked request trailers | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-252898@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/24115
Author: bupt-Yy-young
### Description
In the php-src master snapshot
63b0af4a5c400d93510dca7aa998769609fdc26c (2026-10-04),
the built-in CLI server's HTTP header-size accounting appears not to include chunked-request
trailers.
The parser's PARSING_HEADER macro excludes states while F_TRAILING is
set (sapi/cli/php_http_parser.c:204). After the zero-size chunk sets that flag
(:1472-1474), trailer bytes therefore bypass the PHP_HTTP_MAX_HEADER_SIZE
counter/check (:314-318). The CLI server still accumulates trailer field/value bytes
into persistent strings and its per-client header tables
(sapi/cli/php_cli_server.c:1705-1764), with no corresponding trailer-size limit found.
These persistent allocations remain associated with the connection until its request/client teardown
and are not governed by memory_limit.
A client can send a chunked request, start a large trailer field after the zero chunk, and continue
streaming trailer bytes without completing the trailer block. This can grow the php -S
process memory for as long as the connection remains open. The ordinary header cap and
post_max_size do not appear to cover this trailer path.
### Expected behavior
Apply a total byte/count limit to trailers as well as regular headers, and close/reject the request
once it is exceeded.
### Reproduction outline
Start php -S with a trivial document root. Open a raw TCP connection and send a chunked
HTTP/1.1 request whose body ends with 0\r\nX-Fill: , then stream a large value without
completing the trailer section (\r\n\r\n). Observe whether the server process's
RSS grows beyond the normal header-size limit while the connection remains open. I have traced this
statically in the referenced source; I have not run this outline against a compiled build.
This is reported as a robustness/resource-management bug in the development server, not as a claim
about production SAPI deployments.