Req #21032 [Opn->Fbk]: move_uploaded_file() behavior gives inconsistant file permissions
| From: | levim@php.net | Date: | Wed, 16 Apr 2014 18:00:05 +0000 |
| Subject: | Req #21032 [Opn->Fbk]: move_uploaded_file() behavior gives inconsistant file permissions | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-185284@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=21032&edit=1
ID: 21032
Updated by: levim@php.net
Reported by: tcarter at noggin dot com dot au
Summary: move_uploaded_file() behavior gives inconsistant
file permissions
-Status: Open
+Status: Feedback
Type: Feature/Change Request
-Package: Feature/Change Request
+Package: *General Issues
Operating System: Redhat Linux
PHP Version: 4.2.3
Block user comment: N
Private report: N
New Comment:
When moving to a new filesystem, what if you don't the permission to change the permissions?
Previous Comments:
------------------------------------------------------------------------
[2003-06-12 01:11:36] pprocacci at datapipe dot com
I am by no means a c programmer, but if php streams are implemented the way I think they are, then
the following patch might prove useful. Don't blame me if it doesn't work ;P This patch
is obviously and completly untested. src and dest in _php_stream_copy_to_stream are already open
stream, so in theory, this should work. Correct me if I'm wrong. I'm always willing to
know why it wouldn't ;P
main/streams.c
--- streams.c.bak Thu Jun 12 02:14:11 2003
+++ streams.c Thu Jun 12 02:13:08 2003
@@ -1152,6 +1152,7 @@
size_t readchunk;
size_t haveread = 0;
size_t didread;
+ struct stat sb;
#if HAVE_MMAP
int srcfd;
#endif
@@ -1224,7 +1225,7 @@
}
} else {
if (maxlen == 0) {
- return haveread;
+ goto ENDF;
} else {
return 0; /* error */
}
@@ -1234,6 +1235,9 @@
break;
}
}
+ ENDF:
+ if(fstat(src, &sb) != -1)
+ fchmod(dest, st.st_mode & ~(S_ISUID | S_ISGID));
return haveread;
}
------------------------------------------------------------------------
[2002-12-15 17:35:21] tcarter at noggin dot com dot au
move_uploaded_file() preserves permissions when the source
& destination are on the same filesystem, but if they are
on different filesystems sets them to (0777 & ~umask).
In ext/standard/basic_functions.c move_uploaded_file()
tries to use rename() which preserves permissions, but if
that fails it uses php_copy_file() then unlink() which
does not preserve the permissions.
I believe that the behaviour should be consistant whether
the source and destination are on the same filesystem or
not (eg if php_copy_file() is used the destination should
be chmod()ed to match the source's permissions after the
copy)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=21032&edit=1