Bug #67516 [Csd]: wrong mimetypes with finfo_file(filename, FILEINFO_MIME_TYPE)

From: Date: Fri, 25 Nov 2016 14:02:49 +0000
Subject: Bug #67516 [Csd]: wrong mimetypes with finfo_file(filename, FILEINFO_MIME_TYPE)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205634@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67516&edit=1

 ID:                 67516
 Updated by:         cmb@php.net
 Reported by:        spam2 at rhsoft dot net
 Summary:            wrong mimetypes with finfo_file(filename,
                     FILEINFO_MIME_TYPE)
 Status:             Closed
 Type:               Bug
 Package:            Filesystem function related
 Operating System:   Linux
 PHP Version:        7.0.11
 Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

Harald, you may want to read <https://bugs.php.net/how-to-report.php>. :-)


Previous Comments:
------------------------------------------------------------------------
[2016-11-25 13:55:23] ab@php.net

@spam2 at rhsoft dot net, I can only repeat, that your statement is wrong. And probably add, that
the discussion in this form is not expedient.

$ file php-mimetype-bug.gif
php-mimetype-bug.gif: DOS/MBR boot sector

Guess, which stable distribution this is. Your app could be running on it.

The PHP solution is not worse and not better, than the vanilla lib or a package provided by a
distribution. It is a PITA for ext maintainers, not for you. There will be always a file failed to
be recognized correctly - that is not an acceptance criteria for such a broad usage.

I've asked you to contribute by testing, to ensure the state stability with the real data in
your app and to evaluate a possible backport chance. It's up to you. As for me - I retain from
the further discussion of this kind.

Thanks.

------------------------------------------------------------------------
[2016-11-25 12:41:40] spam2 at rhsoft dot net

but there is a promise that it don't take 2 years until some fix is proposed which takes
another 2 or 3 years to make it in a stable release because it's not a fork 

why do i need to build a PHP7.2 snapshot to test "my application" when the sample image is
still available at https://access.thelounge.net/harry/php-mimetype-bug.gif
and the oneliner "echo finfo_file(filename, FILEINFO_MIME_TYPE);" checks if it now
correctly reports a image mimetype

------------------------------------------------------------------------
[2016-11-25 12:20:57] ab@php.net

@spam2 at rhsoft dot net, what you say is not remotely true. There's absolutely no promise a
distribution shipped libmagic is always correct. It would be much more constructive, if you could
deliver a 7.2 test result with your app.

Thanks.

------------------------------------------------------------------------
[2016-11-25 01:22:45] spam2 at rhsoft dot net

given that this bugreport exists for more than 2 years "This is fixed in 7.2" is
disappointing and the fact that one needs to use exec/passthru/popen which is a no-go in any secure
environment but without you reject perfectly sane uplodas or need to accept
application/oectect-stream which means "forget about mime-type checking at all" should
make that clear

it's a completly wrong design decision that PHP needs a modified libmagic instead using the
system ones which reveives reulgary updates and open_basedir is no excuse - you have to check
open_basedir long before you touch libmagic at all

------------------------------------------------------------------------
[2016-11-25 00:01:09] ab@php.net

This is fixed in 7.2 with the libmagic upgrade https://github.com/php/php-src/commit/52f5b9659fa27936d8271c4d7a6874269fbf9534
. A packport into lower branches might be tricky, as libmagic 5.29 has quite some incompatibilities
to the current version - in the data format as well as in the actual code. It could be possible as a
complete upgrade in lower branches, but would mean yet more patching, however the new libmagic needs
to be ensured stable in 7.2 first.

Thanks.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=67516


--
Edit this bug report at https://bugs.php.net/bug.php?id=67516&edit=1


Thread (30 messages)

« previous php.bugs (#205634) next »