Bug #69472 [NEW]: php_sys_readlink ignores misc errors from GetFinalPathNameByHandleA

From: Date: Thu, 16 Apr 2015 18:16:00 +0000
Subject: Bug #69472 [NEW]: php_sys_readlink ignores misc errors from GetFinalPathNameByHandleA
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192138@lists.php.net to get a copy of this message
From:             jan dot starke at t-systems dot com
Operating system: Windows
PHP version:      Irrelevant
Package:          Filesystem function related
Bug Type:         Bug
Bug description:php_sys_readlink ignores misc errors from GetFinalPathNameByHandleA

Description:
------------
The Windows API functions GetFinalPathNameByHandleA, which is used by
php_sys_readlink, has two different ways of returning an error:
 (1) the return value is different from cchFilePath (which is MAXPATHLEN
in php_sys_readlink). This error is raised if the buffer to store the
pathname is not large enough to hold the pathname.
 (2) the return value is zero. This error can be caused by one of
ERROR_PATH_NOT_FOUND, ERROR_NOT_ENOUGH_MEMORY or
ERROR_INVALID_PARAMETER.

Unfortunately, the second case is not handled by php_sys_readlink. As a
result, php_sys_readlink writes an empty string to target and returns 0
as its length, which both is incorrect.

Expected result:
----------------
php_sys_readlink should return -1 if GetFinalPathNameByHandleA returns
0:

<code>

if (dwRet >= MAXPATHLEN || dwRet == 0) {
  return -1;
}

</code>

Actual result:
--------------
if GetFinalPathNameByHandleA returns 0, php_sys_readlink returns 0 :-(

This brakes php_check_specific_open_basedir, which in our case creates
some problems

<code>

if (dwRet >= MAXPATHLEN) {
  return -1;
}

</code>

-- 
Edit bug report at https://bugs.php.net/bug.php?id=69472&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=69472&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=69472&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=69472&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=69472&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=69472&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=69472&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=69472&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=69472&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=69472&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=69472&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=69472&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=69472&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=69472&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69472&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=69472&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=69472&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=69472&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69472&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=69472&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=69472&r=mysqlcfg



Thread (8 messages)

« previous php.bugs (#192138) next »