#14409 [Com]: request for nonexistent file does not return 404 error

From: Date: Wed, 07 May 2003 22:45:34 +0000
Subject: #14409 [Com]: request for nonexistent file does not return 404 error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-39259@lists.php.net to get a copy of this message
ID: 14409 Comment by: romio at netvision dot net dot il Reported By: support at teamITS dot com Status: Closed Bug Type: Apache related Operating System: IRIX64 vega 6.5 04191225 IP27 PHP Version: 4.2.2 New Comment: I applyied the 4.3.0 "patch" basicaly replacing the old cgi_main.c with the downloaded one, compiled and installed. But it seems that the problem still exists. When ever calling to an unexisting file it still gives a 500 error. I have apache 1.3.27 and php 4.3.1 I configured php as follow : ./configure --enable-force-cgi-redirect --enable-safe-mode --with-openssl --with-zlib --with-gdbm --with-mysql --enable-memory-limit --with-gd --with-jpeg-dir=/usr/lib --with-zlib-dir=/usr/lib --with-png-dir=/usr/lib Previous Comments: ------------------------------------------------------------------------ [2003-01-25 16:26:59] shane@php.net This bug has been fixed in CVS. In case this was a PHP problem, snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites in short time. Thank you for the report, and for helping us make PHP better. This is fixed for CGI in both the 4.3 tree and HEAD. 4.3: http://cvs.php.net/co.php/php4/sapi/cgi/cgi_main.c?r=1.190.2.12 5.0: http://cvs.php.net/co.php/php4/sapi/cgi/cgi_main.c?r=1.208 ------------------------------------------------------------------------ [2003-01-21 15:31:33] brian at zyx dot net I've duplicated this on Linux/Apache w/ PHP 4.3.0 running PHP via CGI. Documents that don't return "No input file specified." and the apache logs show a 200 (succesful page retrieval). Nothing is sent to the error log. The problem is that there's no way to track or log bad page requests. This is very very bad. ------------------------------------------------------------------------ [2002-10-22 02:05:57] gs-bugs-php at gluelogic dot com Small addendum. PHP does exit 255 if its target does not exist, but since it has already sent a complete CGI/1.1 HTTP header back to Apache ("Content-type: text/html\n\n"), including the blank line that indicates end of headers, Apache has already parsed and sent a complete 200 OK set of HTTP headers back to the client. No, this is not an Apache bug. Running PHP 4.2.2 as a CGI via an Action directive under Apache 1.3.23 (RedHat patched). From httpd.conf: ## PHP run as a CGI without everyone needing ExecCGI privs AddType application/x-httpd-php .php .php4 .php3 .phtml AddHandler php-script .php .php4 .php3 .phtml Action php-script /lcgi/php ------------------------------------------------------------------------ [2002-10-21 20:40:02] gs-bugs-php at gluelogic dot com By default, the PHP executable runs in CGI mode and produces an HTTP header "Content-type: text/html" Since PHP runs in CGI mode, it should follow the CGI/1.1 specification, which has not changed in so long that it might even pre-date PHP! I refer you to: http://hoohoo.ncsa.uiuc.edu/cgi/out.html If PHP is going to leave something like the following in my Apache error log: PHP Fatal error: Unable to open /pub/a/b/acb.com/index3.html in Unknown on line 0 when it is unable to find a target file, then I would expect it to either return an error page 404 Not Found, or exit non-zero, at which point Apache will return 500 Server Error. Under NO circumstance should a PHP Fatal error return a 200 OK to the client, which is implicitly done by Apache as per the CGI/1.1 spec when Apache receives pieces of a valid HTTP header without "Status: xxx" specified. Incorrect PHP behavior confirmed on PHP 4.2.2 on Linux 2.4.18, RedHat 7.2. PHP custom compiled with: './configure' '--prefix=/usr/local/php' '--enable-memory-limit' '--enable-force-cgi-redirect' '--enable-safe-mode' '--disable-rpath' '--with-mysql' '--with-db3' -Glenn ------------------------------------------------------------------------ [2002-09-23 14:59:17] support at teamITS dot com Re-opening bug report. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/14409 -- Edit this bug report at http://bugs.php.net/?id=14409&edit=1

« previous php.bugs (#39259) next »