Bug #73048 [Ver]: scandir() does not work without permission to parent folder.
| From: | cmb@php.net | Date: | Fri, 09 Sep 2016 23:49:00 +0000 |
| Subject: | Bug #73048 [Ver]: scandir() does not work without permission to parent folder. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203934@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73048&edit=1
ID: 73048
Updated by: cmb@php.net
Reported by: aj at ajhenderson dot com
Summary: scandir() does not work without permission to parent
folder.
Status: Verified
Type: Bug
Package: Directory function related
Operating System: Windows
PHP Version: 7.0.10
Block user comment: N
Private report: N
New Comment:
Thanks for the reproduce script, Damian!
I can't, however, reproduce scandir() failing with PHP 7.0.10 on
Windows 10 Home build 10586.545; instead running the script
produces the output in
<https://gist.github.com/cmb69/eae8211716b11aee2576b5041d07e004>.
Apparently, the permissions are set as intended, as
dir parent
confirms ("Datei nicht gefunden"), while dir parent\child lists
the folder contents.
Previous Comments:
------------------------------------------------------------------------
[2016-09-08 17:25:18] requinix@php.net
When testing, remember that NTFS has permission inheritance.
1. Create parent and child directories
2. Edit permissions on both to disable inheritance (and replace with existing inherited permissions)
3. Remove permissions on parent folder
Commands like dir (dir parent\child) are able to display the contents of the child
directory, however commands like attrib (attrib parent\child) rightfully do not work.
It'd be easy to say that PHP's behavior is intentional/not a bug, however if dir can do it
then I'd think PHP should be able to as well.
<?php
// setup
mkdir("parent") && mkdir("parent\\child") &&
touch("parent\\child\\file.txt");
passthru("icacls parent /inheritance:d"); // so we can remove this user's perms
passthru("icacls parent\\child /inheritance:d"); // so it doesn't inherit
parent's perms
passthru("icacls parent /remove %USERNAME%");
// works
passthru("dir parent\\child");
// does not work
print_r(scandir("parent\\child"));
// cleanup
passthru("icacls parent /grant %USERNAME%:f");
unlink("parent\\child\\file.txt") && rmdir("parent\\child") &&
rmdir("parent");
?>
------------------------------------------------------------------------
[2016-09-08 15:08:06] aj at ajhenderson dot com
Description:
------------
When attempting to scandir() on a folder which the user has permission to, it fails with Access is
Denied (code 5) if the user does not have access to the parent directory as well.
Expected result:
----------------
Scandir should be able to scan the folder that the PHP user has permission to access.
Actual result:
--------------
Access is denied (code 5) returned.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73048&edit=1