Req #42517 [Opn->Fbk]: set_include_path('') doesn't work as expected

From: Date: Sat, 05 May 2018 18:54:25 +0000
Subject: Req #42517 [Opn->Fbk]: set_include_path('') doesn't work as expected
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215079@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=42517&edit=1 ID: 42517 Updated by: requinix@php.net Reported by: php at ideacode dot com Summary: set_include_path('') doesn't work as expected -Status: Open +Status: Feedback Type: Feature/Change Request -Package: Feature/Change Request +Package: *General Issues Operating System: Linux PHP Version: 5.2.4 Block user comment: N Private report: N New Comment: Even with the include_path cleared, absolute and CWD-relative paths will continue to work. I'm not sure how forcing developers to use such a path, like one as simple as __DIR__."/a/b/c.php", adds security to places where path information is not already unknown. Is there still any interest in this? Can someone give more details about a problem this would solve? Previous Comments: ------------------------------------------------------------------------ [2017-07-25 21:28:05] powtac at gmx dot de 1. It seems that only setting at least 1 char "clears" the include_path. This can be tested with checking the (bool) result. Example: set_include_path(' '); 2. It seems that after setting or "unsetting" the include_path still ".:.." is active as path where PHP searches for files. ------------------------------------------------------------------------ [2007-09-02 00:20:51] php at ideacode dot com Description: ------------ There are legitimate "secure-operation" situations when you want the include path wiped out, so that all included files must be explicitly stated. The obvious way to set this is with either: set_include_path(''); // or ini_set('include_path', ''); However, neither one of these sets the include path to '' on the latest version of PHP 4 or PHP 5 in Linux. A non-obvious workaround is to use a whitespace string: set_include_path(' '); // or ini_set('include_path', ' '); which does set the path to ' ' (which hopefully isn't a valid directory!). I believe passing a lambda string to either set_include_path or ini_set('include_path') should set the path to the lambda string. http://bytejar.com/ - Software Lessons Learned the Hard Way Reproduce code: --------------- $original_path = set_include_path(''); Expected result: ---------------- '' === get_include_path(); Actual result: -------------- $original_path === get_include_path(); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=42517&edit=1

« previous php.bugs (#215079) next »