Bug #67516 [Asn->Ver]: wrong mimetypes with finfo_file(filename, FILEINFO_MIME_TYPE)
| From: | cmb@php.net | Date: | Thu, 08 Sep 2016 11:20:24 +0000 |
| Subject: | Bug #67516 [Asn->Ver]: wrong mimetypes with finfo_file(filename, FILEINFO_MIME_TYPE) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203877@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67516&edit=1
ID: 67516
Updated by: cmb@php.net
Reported by: spam2 at rhsoft dot net
Summary: wrong mimetypes with finfo_file(filename,
FILEINFO_MIME_TYPE)
-Status: Assigned
+Status: Verified
Type: Bug
Package: Filesystem function related
Operating System: Linux
PHP Version: 7.0.11
-Assigned To: cmb
+Assigned To:
Block user comment: N
Private report: N
New Comment:
> i guess some format changed and hence to fork libmagic instead
> intrudce a shim-layer for streaming-support and openbase-dir is
> a historical mistake
It appears to me that there had also limitations of libmagic to be
solved. From a quick look at libmagic.patch[1], I see that the
memory management was hard-coded to malloc() and frieds, that
WIN32 might not have been supported at all, that an IS_STRING
macro is defined by libmagic which might clash with Zend's
IS_STRING, and that there also have been some bugs.
I agree, though, that patching an external library is unfortunate,
and the status of current libmagic should be reviewed. Perhaps
there are cleaner solutions possible now.
Patches are welcome!
[1] <https://github.com/php/php-src/blob/master/ext/fileinfo/libmagic.patch>
Previous Comments:
------------------------------------------------------------------------
[2016-09-08 11:20:14] spam2 at rhsoft dot net
BTW:
> it shouldn't be necessary to compile
> with a custom magic.mgc, because you
> could pass a custom magic.mgc directly
> as second parameter to finfo_open()
besides the current issues on Fedora 24 (se above and the otehr bugreport as requested) this
*really* deserves a "php.ini" parameter to make this system-wide *and* exclude the path
from open-basedir checks because it's form the server configuration (like session_savedir
don't need and must not be in the document root for security reasons as long it's not set
in .htaccess or with ini_set)
when one maintains hundrets of websites, including 3rd party code, want his applications to be
portable it's hard to maintain in the finfo_open() call
the whole goal:
if your application refuses a upload and you get the sample file be able to use the systems
file-command and get the same mimetype reported as the php application got by refuse it
------------------------------------------------------------------------
[2016-09-08 11:12:31] spam2 at rhsoft dot net
see https://bugs.php.net/bug.php?id=73046 for
fail to use 'create_data_file.php' on Fedora 24 to get a recent 'fileinfo.so'
------------------------------------------------------------------------
[2016-09-08 10:58:55] spam2 at rhsoft dot net
echo 'finfo_file(filename, FILEINFO_MIME_TYPE)' . "\n";
$finfo_handle = finfo_open(FILEINFO_NONE, '/usr/share/misc/magic.mgc');
echo finfo_file($finfo_handle, $path, FILEINFO_MIME_TYPE) . "\n";
__________________________________________________________
using the 'magic.mgc' from Fedora don't work this way too (besides it's
practically not useable because of application portability and open_basedir-restrictions outside
php.ini) and may explain why "/usr/bin/php ext/fileinfo/create_data_file.php
/usr/share/misc/magic.mgc > ext/fileinfo/data_file.c" leads to a unusable
'fileinfo.so' extension
file-5.25-6.fc24.x86_64
file-libs-5.25-6.fc24.x86_64
https://koji.fedoraproject.org/koji/packageinfo?packageID=418
i guess some format changed and hence to fork libmagic instead intrudce a shim-layer for
streaming-support and openbase-dir is a historical mistake
__________________________________________________________
Notice: finfo_open(): Warning: type `' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `East_Side_Invertationa' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: type `East_Side_Invertationa' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `The_Incinerator_Plant' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: type `The_Incinerator_Plant' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `Takahiro_Laboratories' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: type `Takahiro_Laboratories' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `<protocol bbn-m' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: type `<protocol bbn-m' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `the_Slipgate_Complex' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: type `the_Slipgate_Complex' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `Castle_of_the_Damned' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: type `Castle_of_the_Damned' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `the_Dismal_Oubliette' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: type `the_Dismal_Oubliette' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `Satan's_Dark_Delight' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: type `Satan's_Dark_Delight' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `The_Tower_of_Despair' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: type `The_Tower_of_Despair' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `The_Elder_God_Shrine' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: type `The_Elder_God_Shrine' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Notice: finfo_open(): Warning: offset `Shub-Niggurath's_Pit' invalid in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
------------------------------------------------------------------------
[2016-09-07 13:40:32] cmb@php.net
I can confirm that even latest master reports
"application/octet-sream" for "php-mimtype-bug.gif" with the
bundled magic.
> well, in a perfect world on would be able to update
> 'data_file.c' with the script in the source tree before compile
> PHP, in the real world the file is updates, php builds but it
> don't work
I can't reproduce this (generating a new data_file.c from Debian
Jessie's magic.mgc, compiling and using finfo works fine for me).
Anyhow, please open another ticket with regard to this issue.
However, it shouldn't be necessary to compile with a custom
magic.mgc, because you could pass a custom magic.mgc directly as
second parameter to finfo_open(). Would that work for you, i.e.
would that produce the expected "image/gif"?
------------------------------------------------------------------------
[2016-09-07 09:31:27] spam2 at rhsoft dot net
well, in a perfect world on would be able to update 'data_file.c' with the script in the
source tree before compile PHP, in the real world the file is updates, php builds but it don't
work
what about someone takes afte rmore than a year a look why https://access.thelounge.net/harry/php-mimetype-bug.gif
is recognized as application/octet-stream instead image/gif and considers to update the mime
database?
i don't get all the excuses for not use the system libmagic - for open_basedir and
streams-support one would need nothing else than a tiny wrapper doing that all with a tempfile which
ins finally feeded to the system libmagic instead fork it completly
_______________________________________
%prep
%setup -q -n php-%{version}
%patch1 -p1
# generate 'data_file.c' from bundeled libmagic with current system data
/usr/bin/php ext/fileinfo/create_data_file.php /usr/share/misc/magic.mgc >
ext/fileinfo/data_file.c
_______________________________________
[harry@rh:/data/lounge-daten/php-mimtype-bug]$ php mime.php
/mnt/data/lounge-daten/php-mimtype-bug/1.gif
/usr/bin/file -b --mime-type
image/gif
finfo_file(filename, FILEINFO_MIME_TYPE)
Warning: finfo_open(): Failed to load magic database at '(null)'. in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 15
Warning: finfo_file() expects parameter 1 to be resource, boolean given in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 16
Warning: finfo_close() expects parameter 1 to be resource, boolean given in
/mnt/data/lounge-daten/php-mimtype-bug/mime.php on line 17
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67516
--
Edit this bug report at https://bugs.php.net/bug.php?id=67516&edit=1