Req #75000 [Com]: getcwd() does not raise error when it fails

From: Date: Tue, 15 Aug 2017 02:02:23 +0000
Subject: Req #75000 [Com]: getcwd() does not raise error when it fails
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210681@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75000&edit=1 ID: 75000 Comment by: marco dot agnoli at me dot com Reported by: marco dot agnoli at me dot com Summary: getcwd() does not raise error when it fails Status: Not a bug Type: Feature/Change Request Package: *General Issues Operating System: OS X PHP Version: 7.1.7 Block user comment: N Private report: N New Comment: I have thought about this issue once again and actually getcwd can do some serious damage if used incorrectly. I'm aware that it is unlikely for getcwd() to fail but consider the following piece of code: <?php $path = \getcwd().'/bin/'; system('rm -rf '.\escapeshellarg($path)); ?> Since PHP converts false to an empty string the folder we attempt to remove would be "/bin" and we wouldn't even know about it! Previous Comments: ------------------------------------------------------------------------ [2017-07-28 10:02:54] spam2 at rhsoft dot net because it would a stupid design when i have to wrap every piece in additional checks or use @ to supress errors which has a large performance impact when a return value you can check is so much more clean Returns the current working directory on success, or FALSE on failure what the hell would you gain when that below triggers a random warning? what you have here is a proper error handling - no thans - i don't want the need to spit @getcwd() all around the code and yes we run error_reporting EALL | E_STRICT for 15 years in production on some hundret customers and the admin group receives every 30 minutes a mail with the current state of the global php error-log - so what you don't want is random warnings with no benefit in a proper environment $cwd = getcwd(); if($cwd !== false) { // do something } else { // properly handle the error } ------------------------------------------------------------------------ [2017-07-28 09:33:01] marco dot agnoli at me dot com I know that it is expected behaviour, but why? Can you tell me the reasoning behind it? ------------------------------------------------------------------------ [2017-07-28 09:12:53] kalle@php.net Both these cases are expected behavior for realpath() and getcwd() to be silent and return false. There are potential other functions that mimic similar behaviors, but in the end it is up to the end user to test the return value of these functions ------------------------------------------------------------------------ [2017-07-28 06:12:40] marco dot agnoli at me dot com Same can be said for the realpath function: ``` <?php error_reporting(E_ALL); var_dump(realpath('non-existing-path')); ?> ``` realpath() expects a valid path, so why not raise an error when no valid path was specified? ------------------------------------------------------------------------ [2017-07-28 06:09:04] marco dot agnoli at me dot com Description: ------------ Some functions like chdir() raise an error when they fail, but others like getcwd() don't. I don't see why getcwd() should not raise an error. This makes catching errors more painful than it should be. Test script: --------------- <?php var_dump(getcwd()); // Remove traversal permission for the current directory system('chmod -x '.escapeshellarg(__DIR__)); /** * I would expect an error here * because getcwd() returns false here. */ var_dump(getcwd()); // Restore traversal permission system('chmod +x '.escapeshellarg(__DIR__)); ?> Expected result: ---------------- A warning from PHP that getcwd() failed. Actual result: -------------- getcwd() silently returns false. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75000&edit=1

« previous php.bugs (#210681) next »