Bug #69351 [Com]: recursive mkdir fails with parent (dot dot) directory in path and symlink

From: Date: Wed, 26 Oct 2016 19:42:16 +0000
Subject: Bug #69351 [Com]: recursive mkdir fails with parent (dot dot) directory in path and symlink
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205030@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69351&edit=1

 ID:                 69351
 Comment by:         nemecek at wienfluss dot net
 Reported by:        dave2008 at buchananville dot net
 Summary:            recursive mkdir fails with parent (dot dot)
                     directory in path and symlink
 Status:             Open
 Type:               Bug
 Package:            Directory function related
 PHP Version:        5.4.39
 Block user comment: N
 Private report:     N

 New Comment:

I was investigating this issue for a CMS we use and can confirm the problem for the following PHP
versions:
* 5.4.16
* 5.4.30
* 5.4.38
* 5.4.44
* 5.4.45
* 5.5.14
* 5.5.22
* 5.5.26
* 5.5.28
* 5.5.30
* 5.5.35
* 5.6.0
* 5.6.2
* 5.6.6
* 5.6.12
* 5.6.16
* 5.6.21
* 7.0.6


JFTR:
In the described test case, the call "mkdir('a/d/../e',0755,false);" would
correctly create the path.


Previous Comments:
------------------------------------------------------------------------
[2015-04-01 22:18:53] dave2008 at buchananville dot net

Description:
------------
Running recursive mkdir fails when there is a ".." directory in the path, and a symbolic
link is present:

mkdir('a/d/../e',0755,true);

The problem is that it is is expanding the path string in place instead of following the physical
filesystem.  After it traverses into a/d, the ".." directory actually takes you somewhere
else.  Not to "a".  In bash this is like cd -P.

It worked like this in previous versions (at least on PHP 5.3.3 and before).

Where previous versions of PHP have acted this way, I think it is best for backwards compatibility
for this to work.


It looks like this was broken when the fix for bug #55124 was applied:

it made it use expand_filepath_with_mode() with the CWD_EXPAND.  Maybe it should have used
CWD_REALPATH instead?  Just a guess...

Test script:
---------------
<?php

mkdir('a/b/c',0755,true);
symlink('b/c','a/d');
chmod('a',0555);

mkdir('a/d/../e',0755,true);

Expected result:
----------------
On PHP 5.3.3 it runs with no output

Actual result:
--------------
PHP Warning:  mkdir(): Permission denied in /var/autofs/home/dave/test-recursive-mkdir.php on line 7


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69351&edit=1


Thread (4 messages)

« previous php.bugs (#205030) next »