Re: Re: PHP 4.0 Bug #4439 Updated: PHP doesn't handle content-transfer-encoding header on form-based file upload

From: Date: Sun, 06 Aug 2000 06:21:22 +0000
Subject: Re: Re: PHP 4.0 Bug #4439 Updated: PHP doesn't handle content-transfer-encoding header on form-based file upload
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-27898@lists.php.net to get a copy of this message
On Mon, Jul 31, 2000 at 01:07:13PM -0700, Rasmus Lerdorf wrote: > That is obvious, but I still think lynx should be fixed to look like other > browsers here. If PHP blindly followed RFC-1867, other stuff would have > as well. > > There is a reason the file upload code is in a file called rfc1867.c. I > wrote it to blindly follow that RFC and anything that deviates from the > RFC is likely to break it. It isn't the most solid piece of code around > and could definitely use a rewrite. > > Ragnar, have a look at php4/main/rfc1867.c and see if you can spot the > trouble there. There are actually 3 distinct problems: 1. quotes around nametags in content-disposition. I fixed this in lynx. 2. mime-parts with content-encoding headers. I've fixed php4 to parse the data correctly. The parsing code is really ugly, and this patch fits right in. It doesn't make any attempts to parse the 3. header, it just corrects the offsets for the data-part. patch is attached. Please apply. 3. My variables get a "\n" prepended :( This only happens when using lynx, but I can't see what the bug is. I've attached the trace. I have no idea if this is another lynx-bug or an php-bug. -- Ragnar Kjorstad

POST /login.php HTTP/1.0 Host: localhost Accept: text/html, text/plain, application/msword, text/sgml, image/png, image/jpeg, image/gif, */*;q=0.01 Accept-Encoding: gzip, compress Accept-Language: en Pragma: no-cache Cache-Control: no-cache User-Agent: Lynx/2.8.4dev.6 libwww-FM/2.14 Referer: http://localhost/login.php Cookie2: $Version="1" Cookie: PHPSESSID=ec9ceb90639f83a84658423288a1030d Content-type: multipart/form-data; boundary=xnyLAaB03X Content-length: 733 --xnyLAaB03X Content-Disposition: form-data; name="next" Content-Type: text/plain; charset=iso-8859-1 --xnyLAaB03X Content-Disposition: form-data; name="input" Content-Type: text/plain; charset=iso-8859-1 yes --xnyLAaB03X Content-Disposition: form-data; name="next" Content-Type: text/plain; charset=iso-8859-1 --xnyLAaB03X Content-Disposition: form-data; name="brukarnamn" Content-Type: text/plain; charset=iso-8859-1 eurofoto@ragnark.vestdata.no --xnyLAaB03X Content-Disposition: form-data; name="passord" Content-Type: text/plain; charset=iso-8859-1 XXXXXXXXX --xnyLAaB03X Content-Disposition: form-data; name="login" Content-Type: text/plain; charset=iso-8859-1 Logg inn --xnyLAaB03X-- HTTP/1.1 200 OK Date: Sun, 06 Aug 2000 00:44:25 GMT Server: Apache-AdvancedExtranetServer/1.3.12 (NetRevolution/Linux-Mandrake/14mdk) PHP/4.0.1pl2 X-Powered-By: PHP/4.0.1pl2 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-cache, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html <HTML> </HTML> --- php-4.0.1pl2/main/rfc1867.c.orig Sat Aug 5 18:44:15 2000 +++ php-4.0.1pl2/main/rfc1867.c Sat Aug 5 20:37:31 2000 @@ -59,7 +59,7 @@ */ static void php_mime_split(char *buf, int cnt, char *boundary, zval *array_ptr) { - char *ptr, *loc, *loc2, *s, *name, *filename, *u, *fn; + char *ptr, *loc, *loc2, *loc3, *s, *name, *filename, *u, *fn; int len, state = 0, Done = 0, rem, urem; int eolsize; long bytes, max_file_size = 0; @@ -111,7 +111,7 @@ if (rem < 31) { SAFE_RETURN; } - php_error(E_WARNING, "File Upload Mime headers garbled [%c%c%c%c%c]", *ptr, *(ptr + 1), *(ptr + 2), *(ptr + 3), *(ptr + 4)); + php_error(E_WARNING, "File Upload Mime headers garbled ptr: [%c%c%c%c%c]", *ptr, *(ptr + 1), *(ptr + 2), *(ptr + 3), *(ptr + 4)); SAFE_RETURN; } loc = memchr(ptr, '\n', rem); @@ -120,7 +120,7 @@ name += 7; s = memchr(name, '\"', loc - name); if (!s) { - php_error(E_WARNING, "File Upload Mime headers garbled [%c%c%c%c%c]", *name, *(name + 1), *(name + 2), *(name + 3), *(name + 4)); + php_error(E_WARNING, "File Upload Mime headers garbled name: [%c%c%c%c%c]", *name, *(name + 1), *(name + 2), *(name + 3), *(name + 4)); SAFE_RETURN; } if (namebuf) { @@ -157,7 +157,7 @@ filename += 11; s = memchr(filename, '\"', loc - filename); if (!s) { - php_error(E_WARNING, "File Upload Mime headers garbled [%c%c%c%c%c]", *filename, *(filename + 1), *(filename + 2), *(filename + 3), *(filename + 4)); + php_error(E_WARNING, "File Upload Mime headers garbled filename: [%c%c%c%c%c]", *filename, *(filename + 1), *(filename + 2), *(filename + 3), *(filename + 4)); SAFE_RETURN; } if (filenamebuf) { @@ -217,8 +217,18 @@ *(loc2 - 1) = '\n'; } - rem -= 2; - ptr += 2; + loc3=memchr(loc2+1, '\n', rem-1); + if (loc3==NULL) { + php_error(E_WARNING, "File Upload Mime headers garbled header3: [%c%c%c%c%c]", *loc2, *(loc2 + 1), *(loc2 + 2), *(loc2 + 3), *(loc2 + 4)); + SAFE_RETURN; + } + if (loc3 - loc2 > 2) { /* we have a third header */ + rem -= (ptr-loc3)+3; + ptr = loc3+3; + } else { + rem -= (ptr-loc3)+1; + ptr = loc3+1; + } } } break;
« previous php.dev (#27898) next »