Bug #49184 [Com]: INPUT_SERVER returns NULL for set variables (CLI)

From: Date: Fri, 12 Jan 2018 19:43:39 +0000
Subject: Bug #49184 [Com]: INPUT_SERVER returns NULL for set variables (CLI)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213508@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=49184&edit=1 ID: 49184 Comment by: m dot patrushev at pitanik dot de Reported by: m dot kurzyna at crystalpoint dot pl Summary: INPUT_SERVER returns NULL for set variables (CLI) Status: Verified Type: Bug Package: Filter related Operating System: * PHP Version: 5.*, 6 (2009-08-07) Block user comment: N Private report: N New Comment: still a problem in 2018 on Versions: 5.6.30 7.1.10 Previous Comments: ------------------------------------------------------------------------ [2017-01-23 07:44:48] dclarke at blastwave dot org Still a valid bug in 5.6.30 : bash-4.3$ ./php-5.6.30_SunOS5.10_sparcv9.001/sapi/cli/php --version PHP 5.6.30 (cli) (built: Jan 23 2017 01:16:31) Copyright (c) 1997-2016 The PHP Group Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies bash-4.3$ cat foo_var_dump.php <?php var_dump( filter_input(INPUT_SERVER,'SOME_ENV_NAME', FILTER_SANITIZE_STRING), $_SERVER['SOME_ENV_NAME'] ); ?> bash-4.3$ SOME_ENV_NAME=this_stuff ./php-5.6.30_SunOS5.10_sparcv9.001/sapi/cli/php foo_var_dump.php NULL string(10) "this_stuff" It may be worth running a trace through the calls and I did build with full debug sysmbols so this is possible. At least on Solaris. ------------------------------------------------------------------------ [2014-10-28 14:40:38] cb at lathspell dot de If you don't care about fixing this bugs for *years*, please be at least so kind to document that it is "not intended" to be used from CLI. ------------------------------------------------------------------------ [2014-02-05 12:55:52] jpswade at gmail dot com It seems this bug still appears in PHP v5.4.24 and has done for over 6 years: * http://www.php.net/manual/en/function.filter-input.php#77307 The general advice is "do not access superglobal $_server array directly" and the solution is to use the filter_input() function instead. * http://stackoverflow.com/questions/19767894/warning-do-not-access-superglobal-post-array-directly-on-netbeans-7-4-for-ph However, this is a show stopper as you can't fully follow this through because all of the INPUT_SERVER variables return NULL. Is PHP serious about not accessing superglobals directly or is this incorrect advice? ------------------------------------------------------------------------ [2011-02-01 23:19:12] mjk at emmjaykay dot org Looking at the filter_input() call in filter.c:747 on 5.3.5, it looks like the call to zend_hash_find() fails. (gdb) call zend_hash_display(input->value->ht) SCRIPT_FILENAME <==> 0x537C323A SCRIPT_NAME <==> 0x9B9D269A PATH_TRANSLATED <==> 0x3A4E2C63 PHP_SELF <==> 0xBD55DE96 DOCUMENT_ROOT <==> 0x1DB85847 DOCUMENT_ROOT <==> 0x1DB85847 PATH_TRANSLATED <==> 0x3A4E2C63 SCRIPT_FILENAME <==> 0x537C323A SCRIPT_NAME <==> 0x9B9D269A PHP_SELF <==> 0xBD55DE96 (gdb) So I guess ENV_NAME never gets put in there at all? ------------------------------------------------------------------------ [2009-08-07 10:20:34] jani@php.net This is quite strange, propably caused by bad design of the filter extension. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=49184 -- Edit this bug report at https://bugs.php.net/bug.php?id=49184&edit=1

« previous php.bugs (#213508) next »