Bug #67516 [Csd]: wrong mimetypes with finfo_file(filename, FILEINFO_MIME_TYPE)
| From: | ab@php.net | Date: | Fri, 25 Nov 2016 13:55:30 +0000 |
| Subject: | Bug #67516 [Csd]: wrong mimetypes with finfo_file(filename, FILEINFO_MIME_TYPE) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205633@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67516&edit=1
ID: 67516
Updated by: ab@php.net
Reported by: spam2 at rhsoft dot net
Summary: wrong mimetypes with finfo_file(filename,
FILEINFO_MIME_TYPE)
Status: Closed
Type: Bug
Package: Filesystem function related
Operating System: Linux
PHP Version: 7.0.11
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
@spam2 at rhsoft dot net, I can only repeat, that your statement is wrong. And probably add, that
the discussion in this form is not expedient.
$ file php-mimetype-bug.gif
php-mimetype-bug.gif: DOS/MBR boot sector
Guess, which stable distribution this is. Your app could be running on it.
The PHP solution is not worse and not better, than the vanilla lib or a package provided by a
distribution. It is a PITA for ext maintainers, not for you. There will be always a file failed to
be recognized correctly - that is not an acceptance criteria for such a broad usage.
I've asked you to contribute by testing, to ensure the state stability with the real data in
your app and to evaluate a possible backport chance. It's up to you. As for me - I retain from
the further discussion of this kind.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2016-11-25 12:41:40] spam2 at rhsoft dot net
but there is a promise that it don't take 2 years until some fix is proposed which takes
another 2 or 3 years to make it in a stable release because it's not a fork
why do i need to build a PHP7.2 snapshot to test "my application" when the sample image is
still available at https://access.thelounge.net/harry/php-mimetype-bug.gif
and the oneliner "echo finfo_file(filename, FILEINFO_MIME_TYPE);" checks if it now
correctly reports a image mimetype
------------------------------------------------------------------------
[2016-11-25 12:20:57] ab@php.net
@spam2 at rhsoft dot net, what you say is not remotely true. There's absolutely no promise a
distribution shipped libmagic is always correct. It would be much more constructive, if you could
deliver a 7.2 test result with your app.
Thanks.
------------------------------------------------------------------------
[2016-11-25 01:22:45] spam2 at rhsoft dot net
given that this bugreport exists for more than 2 years "This is fixed in 7.2" is
disappointing and the fact that one needs to use exec/passthru/popen which is a no-go in any secure
environment but without you reject perfectly sane uplodas or need to accept
application/oectect-stream which means "forget about mime-type checking at all" should
make that clear
it's a completly wrong design decision that PHP needs a modified libmagic instead using the
system ones which reveives reulgary updates and open_basedir is no excuse - you have to check
open_basedir long before you touch libmagic at all
------------------------------------------------------------------------
[2016-11-25 00:01:09] ab@php.net
This is fixed in 7.2 with the libmagic upgrade https://github.com/php/php-src/commit/52f5b9659fa27936d8271c4d7a6874269fbf9534
. A packport into lower branches might be tricky, as libmagic 5.29 has quite some incompatibilities
to the current version - in the data format as well as in the actual code. It could be possible as a
complete upgrade in lower branches, but would mean yet more patching, however the new libmagic needs
to be ensured stable in 7.2 first.
Thanks.
------------------------------------------------------------------------
[2016-09-09 07:50:43] spam2 at rhsoft dot net
Fedora tickets - sorry, but there where over the years way too much not php related bugreports and
searching for "file" which is the package name leads to nowhere
anyways, there needs to be done something that PHP drifts that far form the rest of the world in
file detection - if i allow application/octet-stream for image extensions i can skip the complete
checks at all
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67516
--
Edit this bug report at https://bugs.php.net/bug.php?id=67516&edit=1