Edit report at https://bugs.php.net/bug.php?id=74866&edit=1
ID: 74866
Comment by: spam2 at rhsoft dot net
Reported by: sailormax at inbox dot lv
Summary: extension_dir = "./ext" now use current directory
for base
Status: Verified
Type: Bug
Package: Dynamic loading
Operating System: Windows 10
PHP Version: 7.2.0alpha3
Assigned To: francois
Block user comment: N
Private report: N
New Comment:
frankly people should *really* stop using relative paths at all for configurations - subscribe to
bugtraq@securityfocus.com and it don't take that long to realize how stupid such configurations
are
Previous Comments:
------------------------------------------------------------------------
[2017-07-06 18:27:06] ab@php.net
@sailormax at inbox dot lv are you sure your php dir is not on PATH?
@requinix the explanation is not correct. It never worked the way it'd search relative to the
binary image directory, and unlikely ever will. See this docs
https://msdn.microsoft.com/en-us/library/windows/desktop/ms682586%28v=vs.85%29.aspx?f=255&MSPPError=-2147217396https://msdn.microsoft.com/en-us/library/windows/desktop/ms684175%28v=vs.85%29.aspx?f=255&MSPPError=-2147217396
In particular, this quote
[start]
The first directory searched is the directory containing the image file used to create the calling
process (for more information, see the CreateProcess function). Doing this allows private
dynamic-link library (DLL) files associated with a process to be found without adding the
process's installed directory to the PATH environment variable. If a relative path is
specified, the entire relative path is appended to every token in the DLL search path list.
[end]
Disregarding that, the patch is a really breaching change. The name like
"php_php_bz2.dll.dll" tells, it doesn't even check the ext filename already has a
suffix. More breaches are to expect on Windows
Thanks.
------------------------------------------------------------------------
[2017-07-06 15:11:47] requinix@php.net
(...and tsrm_win32_access looks relative to the current working directory.)
------------------------------------------------------------------------
[2017-07-06 15:10:37] requinix@php.net
Caused by the extension loading changes added in alpha3.
https://wiki.php.net/rfc/load-ext-by-namehttps://github.com/php/php-src/pull/1741
alpha2 constructed a DLL filename and went straight to DL_LOAD/LoadLibrary, which looks relative to
the process.
alpha3 also constructs a filename but first tests the path with VCWD_ACCESS/tsrm_win32_access, which
itself tests access to the parent directory.
------------------------------------------------------------------------
[2017-07-06 12:27:10] sailormax at inbox dot lv
Description:
------------
Early builds works with "./" in extension_dir setting as with directory of
php.exe
Start from 7.2alpha3 "./" in extension_dir setting PHP start to understand as
current directory.
In result if start php.exe from any other directory, it try to load extensions from current
directory.
Test script:
---------------
php.ini:
extension_dir = ".\ext"
extension=php_bz2.dll
exec php from parent directory:
> php\php.exe --version
Expected result:
----------------
PHP 7.2.0alpha3 (cli) ...
Actual result:
--------------
Warning: Cannot access dynamic library 'php_bz2.dll' (tried : ext\php_bz2.dll,
ext\php_php_bz2.dll.dll) in Unknown on line 0
PHP 7.2.0alpha3 (cli) ...
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74866&edit=1