Bug #71385 [NEW]: require* and include* do not detect input/output error

From: Date: Sat, 16 Jan 2016 00:06:42 +0000
Subject: Bug #71385 [NEW]: require* and include* do not detect input/output error
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198699@lists.php.net to get a copy of this message
From:             salsi at icosaedro dot it
Operating system: Slackware 14.1
PHP version:      master-Git-2016-01-16 (Git)
Package:          Streams related
Bug Type:         Bug
Bug description:require* and include* do not detect input/output error

Description:
------------
Possibly related: fread() does not detect file access error
(https://bugs.php.net/bug.php?id=71384).

Trying to include an unreadable file, the require* and include* family
of statements do not to detect the problem; no error nor exception
whatsoever.

The simplest way to simulate an unreadable file on Linux is to read
/proc/self/mem, a file that can be successfully opened but cannot be
read from the very beginning (credits for this trick:
http://unix.stackexchange.com/a/6302):

	$ cat /proc/self/mem
	cat: /proc/self/mem: Input/output error

A simple test made with gcc C confirms that fopen() succeeds while
fread() gives input/output error.

Under PHP, instead, no errors are detected, and that file can be
"required", as the following test script proves. Since "requiring" a
file means that the code that follows depends on it, there might be also
safety and security profiles involved.



Test script:
---------------
<?php
echo "PHP version: ", PHP_VERSION, "\n";
// set safe test environment:
error_reporting(-1);
ini_set("track_errors", "1");

// maps errors to ErrorException:
function my_error_handler($errno, $message) {
	throw new ErrorException($message);
}
set_error_handler("my_error_handler");

define("UNREADABLE", "/proc/self/mem");
require UNREADABLE;
//require_once UNREADABLE;
//include UNREADABLE;
//include_once UNREADABLE;

echo "Just testing if error detection is still on:\n";
require "this file does not exist!";
?>

Expected result:
----------------
PHP version: 7.1.0-dev
(exception on the first fread() telling the file is unreadable)

Actual result:
--------------
PHP version: 7.1.0-dev
Just testing if error detection is still on:
PHP Warning:  Uncaught ErrorException: require(this file does not
exist!): failed to open stream: No such file or directory in
/home/salsi/src/phplint/bug-require-unreadable-file.php:9
Stack trace:
#0 /home/salsi/src/phplint/bug-require-unreadable-file.php(20):
my_error_handler(2, 'require(this fi...', '/home/salsi/src...', 20,
Array)
#1 /home/salsi/src/phplint/bug-require-unreadable-file.php(20):
require()
#2 {main}
  thrown in /home/salsi/src/phplint/bug-require-unreadable-file.php on
line 9
Warning: Uncaught ErrorException: require(this file does not exist!):
failed to open stream: No such file or directory in
/home/salsi/src/phplint/bug-require-unreadable-file.php:9
Stack trace:
#0 /home/salsi/src/phplint/bug-require-unreadable-file.php(20):
my_error_handler(2, 'require(this fi...', '/home/salsi/src...', 20,
Array)
#1 /home/salsi/src/phplint/bug-require-unreadable-file.php(20):
require()
#2 {main}
  thrown in /home/salsi/src/phplint/bug-require-unreadable-file.php on
line 9
PHP Fatal error:  main(): Failed opening required 'this file does not
exist!' (include_path='.') in
/home/salsi/src/phplint/bug-require-unreadable-file.php on line 20
Fatal error: main(): Failed opening required 'this file does not exist!'
(include_path='.') in
/home/salsi/src/phplint/bug-require-unreadable-file.php on line 20

(puzzled by this error message displayed twice, but this is not the
subject of this issue anyway, any suggestion appreciated :-)



-- 
Edit bug report at https://bugs.php.net/bug.php?id=71385&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=71385&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=71385&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=71385&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=71385&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=71385&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=71385&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=71385&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=71385&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=71385&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=71385&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=71385&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=71385&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=71385&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71385&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=71385&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=71385&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=71385&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71385&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=71385&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=71385&r=mysqlcfg



Thread (4 messages)

« previous php.bugs (#198699) next »