Req #75000 [Com]: getcwd() does not raise error when it fails
| From: | marco dot agnoli at me dot com | Date: | Tue, 15 Aug 2017 02:02:23 +0000 |
| Subject: | Req #75000 [Com]: getcwd() does not raise error when it fails | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210681@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75000&edit=1
ID: 75000
Comment by: marco dot agnoli at me dot com
Reported by: marco dot agnoli at me dot com
Summary: getcwd() does not raise error when it fails
Status: Not a bug
Type: Feature/Change Request
Package: *General Issues
Operating System: OS X
PHP Version: 7.1.7
Block user comment: N
Private report: N
New Comment:
I have thought about this issue once again and actually getcwd can do some serious damage if used
incorrectly.
I'm aware that it is unlikely for getcwd() to fail but consider the following piece of code:
<?php
$path = \getcwd().'/bin/';
system('rm -rf '.\escapeshellarg($path));
?>
Since PHP converts false to an empty string the folder we attempt to remove would be
"/bin" and we wouldn't even know about it!
Previous Comments:
------------------------------------------------------------------------
[2017-07-28 10:02:54] spam2 at rhsoft dot net
because it would a stupid design when i have to wrap every piece in additional checks or use @ to
supress errors which has a large performance impact when a return value you can check is so much
more clean
Returns the current working directory on success, or FALSE on failure
what the hell would you gain when that below triggers a random warning?
what you have here is a proper error handling - no thans - i don't want the need to spit
@getcwd() all around the code and yes we run error_reporting EALL | E_STRICT for 15 years in
production on some hundret customers and the admin group receives every 30 minutes a mail with the
current state of the global php error-log - so what you don't want is random warnings with no
benefit in a proper environment
$cwd = getcwd();
if($cwd !== false)
{
// do something
}
else
{
// properly handle the error
}
------------------------------------------------------------------------
[2017-07-28 09:33:01] marco dot agnoli at me dot com
I know that it is expected behaviour, but why?
Can you tell me the reasoning behind it?
------------------------------------------------------------------------
[2017-07-28 09:12:53] kalle@php.net
Both these cases are expected behavior for realpath() and getcwd() to be silent and return false.
There are potential other functions that mimic similar behaviors, but in the end it is up to the end
user to test the return value of these functions
------------------------------------------------------------------------
[2017-07-28 06:12:40] marco dot agnoli at me dot com
Same can be said for the
realpath function:
```
<?php
error_reporting(E_ALL);
var_dump(realpath('non-existing-path'));
?>
```
realpath() expects a valid path, so why not raise an error when no valid path was specified?
------------------------------------------------------------------------
[2017-07-28 06:09:04] marco dot agnoli at me dot com
Description:
------------
Some functions like chdir() raise an error when they fail, but others like getcwd() don't.
I don't see why getcwd() should not raise an error.
This makes catching errors more painful than it should be.
Test script:
---------------
<?php
var_dump(getcwd());
// Remove traversal permission for the current directory
system('chmod -x '.escapeshellarg(__DIR__));
/**
* I would expect an error here
* because getcwd() returns false here.
*/
var_dump(getcwd());
// Restore traversal permission
system('chmod +x '.escapeshellarg(__DIR__));
?>
Expected result:
----------------
A warning from PHP that getcwd() failed.
Actual result:
--------------
getcwd() silently returns false.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75000&edit=1