Req #70845 [Opn]: ip2long should not fail with number starting with zero

From: Date: Sun, 03 Jul 2016 11:06:36 +0000
Subject: Req #70845 [Opn]: ip2long should not fail with number starting with zero
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202015@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70845&edit=1

 ID:                 70845
 Updated by:         cmb@php.net
 Reported by:        raffaellobertini at gmail dot com
 Summary:            ip2long should not fail with number starting with
                     zero
 Status:             Open
 Type:               Feature/Change Request
 Package:            Network related
 Operating System:   centos6.5
 PHP Version:        5.4.45
 Block user comment: N
 Private report:     N

 New Comment:

ip_clean() could be easily implemented in userland, though, for
instance:

    <?php
    function ip_clean(string $ip) : ?string
    {
        return implode(
            '.',
            array_map(
                function ($el) {
                    return (int) $el;
                },
                explode('.', $ip)
            )
        );
    }

See <https://3v4l.org/NcNg7>.


Previous Comments:
------------------------------------------------------------------------
[2016-07-02 15:39:50] raffaellobertini at gmail dot com

@cmb@php.net you are perfectly right!

I would like to suggest (raw idea), instead of changing ip2long(), to built-in another helper
function instead, that process the IP in string format and "clean" it and make it concise.

it will be something like:

    function ip_clean(string $ip) : ?string { ... }


and just process splitting by dot returning in a "correct" format the string to be
processed further if required.

------------------------------------------------------------------------
[2016-07-01 19:28:20] cmb@php.net

I can confirm the behavior, see <https://3v4l.org/tr4B3>.

ip2long() is defined in ext/standard/basic_functions.c[1].
However, it appears to me the "culprit" is inet_addr() and/or
inet_pton() to which PHP delegates without much further
processing. I don't know about inet_pton(), but indeed inet_addr()
interprets fields with a leading zero as octal integers[2], so in
this case it fails. As this behavior is documented[3] and makes
sense, I'm changing this ticket to feature request.

Changing the behavior of ip2long() would be possible, but that
would obviously cause a BC break, and as such likely would require
the RFC process[4].

[1] <https://github.com/php/php-src/blob/php-7.0.8/ext/standard/basic_functions.c#L3938-L3974>
[2] <http://publibn.boulder.ibm.com/doc_link/en_US/a_doc_lib/libs/commtrf2/inet_addr.htm>
[3] <http://php.net/manual/en/function.ip2long.php>
[4] <https://wiki.php.net/rfc/howto>

------------------------------------------------------------------------
[2015-12-19 01:48:55] ajf@php.net

This is merely speculation, but I think it may be interpreting '096' as octal due to the
leading zero. '9' is not a valid octal digit, so in that case, it would be an invalid IP
address.

------------------------------------------------------------------------
[2015-11-03 16:28:15] raffaellobertini at gmail dot com

Description:
------------
just run ip2long('195.194.213.096') it will return false instead of 
interpreting the string as '195,194.213.96'

if you point me to the code i fix myself. I mean, the function is not robust.
cannot crash for a number that is '096' that it will be 96 as integer. 



Test script:
---------------
ip2long('195.194.213.096') === ip2long('195,194.213.96')


//anyway the code to convert into packed format is quite easy, but It is not nice that I cannot rely
on php built in function....



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70845&edit=1


Thread (6 messages)

« previous php.bugs (#202015) next »