Skip to content

Commit bb4dbbc

Browse files
committed
Merge branch 'PHP-7.4' into PHP-8.0
* PHP-7.4: Fix #80849: HTTP Status header truncation
2 parents fc6656e + a054ef2 commit bb4dbbc

File tree

5 files changed

+63
-8
lines changed

5 files changed

+63
-8
lines changed

NEWS

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,9 @@ PHP NEWS
55
- Core:
66
. Fixed bug #72595 (php_output_handler_append illegal write access). (cmb)
77

8+
- CGI:
9+
. Fixed bug #80849 (HTTP Status header truncation). (cmb)
10+
811
- Standard:
912
. Fixed bug #72146 (Integer overflow on substr_replace). (cmb)
1013

sapi/cgi/cgi_main.c

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -383,7 +383,7 @@ static int sapi_cgi_send_headers(sapi_headers_struct *sapi_headers)
383383

384384
if (CGIG(rfc2616_headers) && SG(sapi_headers).http_status_line) {
385385
char *s;
386-
len = slprintf(buf, SAPI_CGI_MAX_HEADER_LENGTH, "%s\r\n", SG(sapi_headers).http_status_line);
386+
len = slprintf(buf, SAPI_CGI_MAX_HEADER_LENGTH, "%s", SG(sapi_headers).http_status_line);
387387
if ((s = strchr(SG(sapi_headers).http_status_line, ' '))) {
388388
response_status = atoi((s + 1));
389389
}
@@ -400,7 +400,7 @@ static int sapi_cgi_send_headers(sapi_headers_struct *sapi_headers)
400400
(s - SG(sapi_headers).http_status_line) >= 5 &&
401401
strncasecmp(SG(sapi_headers).http_status_line, "HTTP/", 5) == 0
402402
) {
403-
len = slprintf(buf, sizeof(buf), "Status:%s\r\n", s);
403+
len = slprintf(buf, sizeof(buf), "Status:%s", s);
404404
response_status = atoi((s + 1));
405405
} else {
406406
h = (sapi_header_struct*)zend_llist_get_first_ex(&sapi_headers->headers, &pos);
@@ -423,16 +423,17 @@ static int sapi_cgi_send_headers(sapi_headers_struct *sapi_headers)
423423
err++;
424424
}
425425
if (err->str) {
426-
len = slprintf(buf, sizeof(buf), "Status: %d %s\r\n", SG(sapi_headers).http_response_code, err->str);
426+
len = slprintf(buf, sizeof(buf), "Status: %d %s", SG(sapi_headers).http_response_code, err->str);
427427
} else {
428-
len = slprintf(buf, sizeof(buf), "Status: %d\r\n", SG(sapi_headers).http_response_code);
428+
len = slprintf(buf, sizeof(buf), "Status: %d", SG(sapi_headers).http_response_code);
429429
}
430430
}
431431
}
432432
}
433433

434434
if (!has_status) {
435435
PHPWRITE_H(buf, len);
436+
PHPWRITE_H("\r\n", 2);
436437
ignore_status = 1;
437438
}
438439
}

sapi/cgi/tests/bug80849-cgi.phpt

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
--TEST--
2+
Bug #80849 (HTTP Status header truncation)
3+
--CGI--
4+
--FILE--
5+
<?php
6+
header('HTTP/1.1 201 ' . str_repeat('A', 1014), true);
7+
?>
8+
--EXPECTHEADERS--
9+
Status: 201 AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
10+
--EXPECT--

sapi/fpm/fpm/fpm_main.c

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -323,7 +323,7 @@ static int sapi_cgi_send_headers(sapi_headers_struct *sapi_headers) /* {{{ */
323323

324324
if (CGIG(rfc2616_headers) && SG(sapi_headers).http_status_line) {
325325
char *s;
326-
len = slprintf(buf, SAPI_CGI_MAX_HEADER_LENGTH, "%s\r\n", SG(sapi_headers).http_status_line);
326+
len = slprintf(buf, SAPI_CGI_MAX_HEADER_LENGTH, "%s", SG(sapi_headers).http_status_line);
327327
if ((s = strchr(SG(sapi_headers).http_status_line, ' '))) {
328328
response_status = atoi((s + 1));
329329
}
@@ -340,7 +340,7 @@ static int sapi_cgi_send_headers(sapi_headers_struct *sapi_headers) /* {{{ */
340340
(s - SG(sapi_headers).http_status_line) >= 5 &&
341341
strncasecmp(SG(sapi_headers).http_status_line, "HTTP/", 5) == 0
342342
) {
343-
len = slprintf(buf, sizeof(buf), "Status:%s\r\n", s);
343+
len = slprintf(buf, sizeof(buf), "Status:%s", s);
344344
response_status = atoi((s + 1));
345345
} else {
346346
h = (sapi_header_struct*)zend_llist_get_first_ex(&sapi_headers->headers, &pos);
@@ -363,16 +363,17 @@ static int sapi_cgi_send_headers(sapi_headers_struct *sapi_headers) /* {{{ */
363363
err++;
364364
}
365365
if (err->str) {
366-
len = slprintf(buf, sizeof(buf), "Status: %d %s\r\n", SG(sapi_headers).http_response_code, err->str);
366+
len = slprintf(buf, sizeof(buf), "Status: %d %s", SG(sapi_headers).http_response_code, err->str);
367367
} else {
368-
len = slprintf(buf, sizeof(buf), "Status: %d\r\n", SG(sapi_headers).http_response_code);
368+
len = slprintf(buf, sizeof(buf), "Status: %d", SG(sapi_headers).http_response_code);
369369
}
370370
}
371371
}
372372
}
373373

374374
if (!has_status) {
375375
PHPWRITE_H(buf, len);
376+
PHPWRITE_H("\r\n", 2);
376377
ignore_status = 1;
377378
}
378379
}

sapi/fpm/tests/bug80849-fpm.phpt

Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
--TEST--
2+
Bug #80849 (HTTP Status header truncation)
3+
--SKIPIF--
4+
<?php include "skipif.inc"; ?>
5+
--FILE--
6+
<?php
7+
require_once "tester.inc";
8+
9+
$cfg = <<<EOT
10+
[global]
11+
error_log = {{FILE:LOG}}
12+
[unconfined]
13+
listen = {{ADDR}}
14+
pm = dynamic
15+
pm.max_children = 5
16+
pm.start_servers = 1
17+
pm.min_spare_servers = 1
18+
pm.max_spare_servers = 3
19+
EOT;
20+
21+
$code = <<<EOT
22+
<?php
23+
header('HTTP/1.1 201 ' . str_repeat('A', 1014), true);
24+
EOT;
25+
26+
$tester = new FPM\Tester($cfg, $code);
27+
$tester->start();
28+
$tester->expectLogStartNotices();
29+
$tester
30+
->request()
31+
->expectHeader('Status', '201 ' . str_repeat('A', 1011));
32+
$tester->terminate();
33+
$tester->close();
34+
?>
35+
--CLEAN--
36+
<?php
37+
require_once "tester.inc";
38+
FPM\Tester::clean();
39+
?>
40+
--EXPECT--

0 commit comments

Comments
 (0)