Edit report at https://bugs.php.net/bug.php?id=67516&edit=1
ID: 67516
Updated by: cmb@php.net
Reported by: spam2 at rhsoft dot net
Summary: wrong mimetypes with finfo_file(filename,
FILEINFO_MIME_TYPE)
Status: Closed
Type: Bug
Package: Filesystem function related
Operating System: Linux
PHP Version: 7.0.11
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Harald, you may want to read <https://bugs.php.net/how-to-report.php>. :-)
Previous Comments:
------------------------------------------------------------------------
[2016-11-25 13:55:23] ab@php.net
@spam2 at rhsoft dot net, I can only repeat, that your statement is wrong. And probably add, that
the discussion in this form is not expedient.
$ file php-mimetype-bug.gif
php-mimetype-bug.gif: DOS/MBR boot sector
Guess, which stable distribution this is. Your app could be running on it.
The PHP solution is not worse and not better, than the vanilla lib or a package provided by a
distribution. It is a PITA for ext maintainers, not for you. There will be always a file failed to
be recognized correctly - that is not an acceptance criteria for such a broad usage.
I've asked you to contribute by testing, to ensure the state stability with the real data in
your app and to evaluate a possible backport chance. It's up to you. As for me - I retain from
the further discussion of this kind.
Thanks.
------------------------------------------------------------------------
[2016-11-25 12:41:40] spam2 at rhsoft dot net
but there is a promise that it don't take 2 years until some fix is proposed which takes
another 2 or 3 years to make it in a stable release because it's not a fork
why do i need to build a PHP7.2 snapshot to test "my application" when the sample image is
still available at https://access.thelounge.net/harry/php-mimetype-bug.gif
and the oneliner "echo finfo_file(filename, FILEINFO_MIME_TYPE);" checks if it now
correctly reports a image mimetype
------------------------------------------------------------------------
[2016-11-25 12:20:57] ab@php.net
@spam2 at rhsoft dot net, what you say is not remotely true. There's absolutely no promise a
distribution shipped libmagic is always correct. It would be much more constructive, if you could
deliver a 7.2 test result with your app.
Thanks.
------------------------------------------------------------------------
[2016-11-25 01:22:45] spam2 at rhsoft dot net
given that this bugreport exists for more than 2 years "This is fixed in 7.2" is
disappointing and the fact that one needs to use exec/passthru/popen which is a no-go in any secure
environment but without you reject perfectly sane uplodas or need to accept
application/oectect-stream which means "forget about mime-type checking at all" should
make that clear
it's a completly wrong design decision that PHP needs a modified libmagic instead using the
system ones which reveives reulgary updates and open_basedir is no excuse - you have to check
open_basedir long before you touch libmagic at all
------------------------------------------------------------------------
[2016-11-25 00:01:09] ab@php.net
This is fixed in 7.2 with the libmagic upgrade https://github.com/php/php-src/commit/52f5b9659fa27936d8271c4d7a6874269fbf9534
. A packport into lower branches might be tricky, as libmagic 5.29 has quite some incompatibilities
to the current version - in the data format as well as in the actual code. It could be possible as a
complete upgrade in lower branches, but would mean yet more patching, however the new libmagic needs
to be ensured stable in 7.2 first.
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67516
--
Edit this bug report at https://bugs.php.net/bug.php?id=67516&edit=1