Bug #69536 [Opn]: Extracted ZipArchive archives have insecure permissions when extracted by OSX
| From: | cmb@php.net | Date: | Wed, 29 Apr 2015 20:37:15 +0000 |
| Subject: | Bug #69536 [Opn]: Extracted ZipArchive archives have insecure permissions when extracted by OSX | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192415@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69536&edit=1
ID: 69536
Updated by: cmb@php.net
Reported by: kevin dot cupp at ellislab dot com
Summary: Extracted ZipArchive archives have insecure
permissions when extracted by OSX
Status: Open
Type: Bug
Package: Zip Related
Operating System: OSX
PHP Version: 5.5.24
Block user comment: N
Private report: N
New Comment:
A slight variation of the supplied test script to make the issue
more easily reproducible:
$zip = new ZipArchive();
$zip->open('69536.zip',ZipArchive::CREATE);
$zip->addFromString('foo','bar');
$zip->close();
Recent versions of PHP set the "version made by" (byte no.
0x2A-0x2B in the archives generated by the test script) to 0x1403,
whereas former PHP versions used 0x1400. 0x14 is the ZIP version,
0x00 means DOS, 0x03 means Unix. I suppose that's what makes the
difference for OS X's native unarchiver.
Previous Comments:
------------------------------------------------------------------------
[2015-04-27 16:13:19] kevin dot cupp at ellislab dot com
Description:
------------
In PHP 5.5 and above, ZipArchive is creating archives that, when extracted by OSX, have its folders
permissions set to 777 and files set to 666. In PHP 5.4, everything defaults to 755. When using a
third-party extractor, such as The Unarchiver for OSX, permissions are normal, so it is only a
problem (to my knowledge) with OSX's native unarchiver.
It could be argued that since it's a problem with OSX's unarchiver, the ball is in their
court. But since it works fine on archives created in <= 5.4, I'm wondering if something
could be done on PHP's end to write its zips in a way that OSX's unarchiver will not
misinterpret, as a lot of folks are creating zips with PHP and a lot of customers are extracting
those zips on their Macs. I'm not expecting original permissions be retained, just that
ZipArchive writes its archives in a way that allows OSX pick a more sane default again, like 755.
Test script:
---------------
$zip = new ZipArchive();
$zip->open('./test.zip', ZIPARCHIVE::CREATE);
$zip->addEmptyDir('archive');
$zip->addFile('./test.php', 'archive/test.php');
$zip->close();
Expected result:
----------------
I expect an archive to be created, that when extracted with OSX's native unarchiver, the files
have a relatively secure default permission applied to them, as in PHP 5.4.
Actual result:
--------------
Extracted files have a permission of 666, folders are 777.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69536&edit=1