Bug #65636 [Opn->Nab]: Stream path cannot contail null char (chr(0))
| From: | cmb@php.net | Date: | Wed, 09 Sep 2015 14:20:35 +0000 |
| Subject: | Bug #65636 [Opn->Nab]: Stream path cannot contail null char (chr(0)) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195912@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65636&edit=1
ID: 65636
Updated by: cmb@php.net
Reported by: bilge at scriptfusion dot com
Summary: Stream path cannot contail null char (chr(0))
-Status: Open
+Status: Not a bug
Type: Bug
Package: Streams related
Operating System: Linux
PHP Version: 5.5.3
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Disallowing null bytes in paths is not a bug, but a deliberate
design decision for security reasons. While PHP can handle strings
which contain null bytes well, most underlying C libraries can't,
because NUL is the customary string delimiter in C. To avoid any
troubles, PHP rejects null bytes in paths in the first place.
Previous Comments:
------------------------------------------------------------------------
[2013-09-19 12:25:26] bixuehujin at gmail dot com
AFAIK, it is not possible to contain null character in a filename path, this is not because of PHP
but the OS.
At the OS level, it seems no way to handle a file contains null characters.
------------------------------------------------------------------------
[2013-09-08 23:02:36] bilge at scriptfusion dot com
Description:
------------
Stream path can contain any character, whether URL encoded or not, except for the null character.
Including a null character in the path raises the following error:
file_get_contents() expects parameter 1 to be a valid path, string given
Both the use case and test suite to support the claims above can be found at https://github.com/Bilge/VerbatimStream/tree/eb185806f9bea3ee65b7d0f3e42dcd27a7b40614
The use case is a custom stream wrapper that takes the path and converts it into a read-only data
stream. The current workaround is to urlencode any path that contains nulls. However, this approach
provides little benefit over the data wrapper. Being able to include nulls directly in the path
would eliminate unnecessary url encoding and decoding in the custom wrapper implementation.
Test script:
---------------
file_get_contents("\000");
//or
file_get_contents("verbatim://\000");
Expected result:
----------------
No error.
Actual result:
--------------
file_get_contents() expects parameter 1 to be a valid path, string given
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65636&edit=1