Bug #74866 [Com]: extension_dir = "./ext" now use current directory for base

From: Date: Thu, 06 Jul 2017 18:38:27 +0000
Subject: Bug #74866 [Com]: extension_dir = "./ext" now use current directory for base
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209865@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74866&edit=1

 ID:                 74866
 Comment by:         spam2 at rhsoft dot net
 Reported by:        sailormax at inbox dot lv
 Summary:            extension_dir = "./ext" now use current directory
                     for base
 Status:             Verified
 Type:               Bug
 Package:            Dynamic loading
 Operating System:   Windows 10
 PHP Version:        7.2.0alpha3
 Assigned To:        francois
 Block user comment: N
 Private report:     N

 New Comment:

frankly people should *really* stop using relative paths at all for configurations - subscribe to
bugtraq@securityfocus.com and it don't take that long to realize how stupid such configurations
are


Previous Comments:
------------------------------------------------------------------------
[2017-07-06 18:27:06] ab@php.net

@sailormax at inbox dot lv are you sure your php dir is not on PATH?

@requinix the explanation is not correct. It never worked the way it'd search relative to the
binary image directory, and unlikely ever will. See this docs

https://msdn.microsoft.com/en-us/library/windows/desktop/ms682586%28v=vs.85%29.aspx?f=255&MSPPError=-2147217396
https://msdn.microsoft.com/en-us/library/windows/desktop/ms684175%28v=vs.85%29.aspx?f=255&MSPPError=-2147217396

In particular, this quote

[start]
The first directory searched is the directory containing the image file used to create the calling
process (for more information, see the CreateProcess function). Doing this allows private
dynamic-link library (DLL) files associated with a process to be found without adding the
process's installed directory to the PATH environment variable. If a relative path is
specified, the entire relative path is appended to every token in the DLL search path list. 
[end]

Disregarding that, the patch is a really breaching change. The name like
"php_php_bz2.dll.dll" tells, it doesn't even check the ext filename already has a
suffix. More breaches are to expect on Windows

Thanks.

------------------------------------------------------------------------
[2017-07-06 15:11:47] requinix@php.net

(...and tsrm_win32_access looks relative to the current working directory.)

------------------------------------------------------------------------
[2017-07-06 15:10:37] requinix@php.net

Caused by the extension loading changes added in alpha3.
https://wiki.php.net/rfc/load-ext-by-name
https://github.com/php/php-src/pull/1741

alpha2 constructed a DLL filename and went straight to DL_LOAD/LoadLibrary, which looks relative to
the process.
alpha3 also constructs a filename but first tests the path with VCWD_ACCESS/tsrm_win32_access, which
itself tests access to the parent directory.

------------------------------------------------------------------------
[2017-07-06 12:27:10] sailormax at inbox dot lv

Description:
------------
Early builds works with "./" in extension_dir setting as with directory of
php.exe

Start from 7.2alpha3 "./" in extension_dir setting PHP start to understand as
current directory.
In result if start php.exe from any other directory, it try to load extensions from current
directory.

Test script:
---------------
php.ini:

extension_dir = ".\ext"
extension=php_bz2.dll

exec php from parent directory:
> php\php.exe --version

Expected result:
----------------
PHP 7.2.0alpha3 (cli) ...

Actual result:
--------------
Warning: Cannot access dynamic library 'php_bz2.dll' (tried : ext\php_bz2.dll,
ext\php_php_bz2.dll.dll) in Unknown on line 0

PHP 7.2.0alpha3 (cli) ...


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74866&edit=1


Thread (14 messages)

« previous php.bugs (#209865) next »