Bug #72625 [Ana]: realpath() fails on very long argument.

From: Date: Sat, 23 Jul 2016 16:17:12 +0000
Subject: Bug #72625 [Ana]: realpath() fails on very long argument.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202532@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72625&edit=1 ID: 72625 Updated by: ab@php.net Reported by: anrdaemon at freemail dot ru Summary: realpath() fails on very long argument. Status: Analyzed Type: Bug Package: Filesystem function related Operating System: Windows PHP Version: 7.0.8 Assigned To: ab Block user comment: N Private report: N New Comment: @cmb, yeah, Windows API won't do any magic with \\?\ prefixed paths. I intentionally left this part, because there is yet no API for all windows versions (starting with 8.1 there is one). Also, that saves some memory operations. While replacing slashes wouldn't cost any memory overhead, so probably could be done. Since this issue is related to composer, probably worth it at least. I'll look to maybe come up with some custom PathCchCanonicalizeEx for lower Windows versions. Thanks. Previous Comments: ------------------------------------------------------------------------ [2016-07-21 23:02:15] cmb@php.net The issue is FindFirstFileW(), which isn't as liberal with regard to the \\?\ prefix as without it. POC: #include <windows.h> int main() { HANDLE h; WIN32_FIND_DATA fd; h = FindFirstFileW(L"C:\\Windows", &fd); printf("%i\n", h != INVALID_HANDLE_VALUE); h = FindFirstFileW(L"C:/Windows", &fd); printf("%i\n", h != INVALID_HANDLE_VALUE); h = FindFirstFileW(L"\\\\?\\C:\\Windows", &fd); printf("%i\n", h != INVALID_HANDLE_VALUE); h = FindFirstFileW(L"\\\\?\\C:/Windows", &fd); printf("%i\n", h != INVALID_HANDLE_VALUE); return 0; } outputs: 1 1 1 0 Neither slashes (nor dots nor double-dots) are converted, as noted on MSDN in the section about "Maximum Path Length Limitation"[1]. It occurs to me that this conversion would have to be done by PHP in the first place. Anatol, what do you think? [1] <https://msdn.microsoft.com/en-us/library/windows/desktop/aa365247(v=vs.85).aspx#maxpath> ------------------------------------------------------------------------ [2016-07-21 18:43:01] cmb@php.net Indeed, can also reproduce with current master. ------------------------------------------------------------------------ [2016-07-21 12:07:02] anrdaemon at freemail dot ru Didn't change. If not made worse. Refined script: <?php $fn = "{$_SERVER['TEMP']}/_test/documents/projects/myproject/vendor/name/library/classpath"; $fn1 = "$fn/../../../../../../../../_test/documents/projects/myproject/vendor/name/library/../../../../../../../_test/documents/projects/myproject/vendor/name/library/classpath"; mkdir($fn, 0777, true); error_log(sprintf("(%u)%s", strlen($fn), $fn)); error_log("=>" . realpath($fn)); error_log(sprintf("(%u)%s", strlen($fn1), $fn1)); error_log("=>" . realpath($fn1)); error_log(sprintf("(%u)%s", strlen(dirname($fn1)), dirname($fn1))); error_log("=>" . realpath(dirname($fn1))); PHP 5.6.23/64 (101)C:\Users\ANRDAE~1\AppData\Local\Temp/_test/documents/projects/myproject/vendor/name/library/classpath =>C:\Users\anrdaemon\AppData\Local\Temp\_test\documents\projects\myproject\vendor\name\library\classpath (266)C:\Users\ANRDAE~1\AppData\Local\Temp/_test/documents/projects/myproject/vendor/name/library/classpath/../../../../../../../../_test/documents/projects/myproject/vendor/name/library/../../../../../../../_test/documents/projects/myproject/vendor/name/library/classpath => (256)C:\Users\ANRDAE~1\AppData\Local\Temp/_test/documents/projects/myproject/vendor/name/library/classpath/../../../../../../../../_test/documents/projects/myproject/vendor/name/library/../../../../../../../_test/documents/projects/myproject/vendor/name/library =>C:\Users\anrdaemon\AppData\Local\Temp\_test\documents\projects\myproject\vendor\name\library PHP 7.0.8/64 (101)C:\Users\ANRDAE~1\AppData\Local\Temp/_test/documents/projects/myproject/vendor/name/library/classpath =>C:\Users\anrdaemon\AppData\Local\Temp\_test\documents\projects\myproject\vendor\name\library\classpath (266)C:\Users\ANRDAE~1\AppData\Local\Temp/_test/documents/projects/myproject/vendor/name/library/classpath/../../../../../../../../_test/documents/projects/myproject/vendor/name/library/../../../../../../../_test/documents/projects/myproject/vendor/name/library/classpath => (256)C:\Users\ANRDAE~1\AppData\Local\Temp/_test/documents/projects/myproject/vendor/name/library/classpath/../../../../../../../../_test/documents/projects/myproject/vendor/name/library/../../../../../../../_test/documents/projects/myproject/vendor/name/library =>C:\Users\anrdaemon\AppData\Local\Temp\_test\documents\projects\myproject\vendor\name\library PHP 7.1.0b1/64 (101)C:\Users\ANRDAE~1\AppData\Local\Temp/_test/documents/projects/myproject/vendor/name/library/classpath =>C:\Users\anrdaemon\AppData\Local\Temp\_test\documents\projects\myproject\vendor\name\library\classpath (266)C:\Users\ANRDAE~1\AppData\Local\Temp/_test/documents/projects/myproject/vendor/name/library/classpath/../../../../../../../../_test/documents/projects/myproject/vendor/name/library/../../../../../../../_test/documents/projects/myproject/vendor/name/library/classpath => (260)\\?\C:\Users\ANRDAE~1\AppData\Local\Temp/_test/documents/projects/myproject/vendor/name/library/classpath/../../../../../../../../_test/documents/projects/myproject/vendor/name/library/../../../../../../../_test/documents/projects/myproject/vendor/name/library => ------------------------------------------------------------------------ [2016-07-20 10:05:00] cmb@php.net That is supposed to be fixed as of PHP 7.1.0alpha2. Please try with a version from <http://windows.php.net/qa/>. ------------------------------------------------------------------------ [2016-07-20 03:53:13] anrdaemon at freemail dot ru Description: ------------ When given a long string (> 260 characters), realpath() and SplFileInfo::getRealPath() both fail to convert path to something sensible and return empty result. However, using dirname() to shorten the input string will result in the function working again. Additionally, PHP reporting "invalid path", if you try to use extended access syntax ('\\?\<path>'). (Oh, and before you say something silly, the sting in example is an equivalent of a real path generated by Composer.) Test script: --------------- <?php $fn = "{$_SERVER['TEMP']}/_test/documents/projects/myproject/vendor/name/library/classpath"; $fn1 = "$fn/../../../../../../../../_test/documents/projects/myproject/vendor/name/library/../../../../../../../_test/documents/projects/myproject/vendor/name/library/classpath"; mkdir($fn, 0777, true); error_log(strlen($fn)); error_log(realpath($fn)); error_log(strlen($fn1)); error_log($fn1); error_log(realpath($fn1)); error_log(strlen(dirname($fn1))); error_log(dirname($fn1)); error_log(realpath(dirname($fn1))); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72625&edit=1

« previous php.bugs (#202532) next »