Req #42517 [Opn->Fbk]: set_include_path('') doesn't work as expected
| From: | requinix@php.net | Date: | Sat, 05 May 2018 18:54:25 +0000 |
| Subject: | Req #42517 [Opn->Fbk]: set_include_path('') doesn't work as expected | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215079@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=42517&edit=1
ID: 42517
Updated by: requinix@php.net
Reported by: php at ideacode dot com
Summary: set_include_path('') doesn't work as expected
-Status: Open
+Status: Feedback
Type: Feature/Change Request
-Package: Feature/Change Request
+Package: *General Issues
Operating System: Linux
PHP Version: 5.2.4
Block user comment: N
Private report: N
New Comment:
Even with the include_path cleared, absolute and CWD-relative paths will continue to work. I'm
not sure how forcing developers to use such a path, like one as simple as
__DIR__."/a/b/c.php", adds security to places where path information is not already
unknown.
Is there still any interest in this? Can someone give more details about a problem this would solve?
Previous Comments:
------------------------------------------------------------------------
[2017-07-25 21:28:05] powtac at gmx dot de
1. It seems that only setting at least 1 char "clears" the include_path. This can be
tested with checking the (bool) result. Example: set_include_path(' ');
2. It seems that after setting or "unsetting" the include_path still ".:.." is
active as path where PHP searches for files.
------------------------------------------------------------------------
[2007-09-02 00:20:51] php at ideacode dot com
Description:
------------
There are legitimate "secure-operation" situations when you want the include path wiped
out, so that all included files must be explicitly stated.
The obvious way to set this is with either:
set_include_path(''); // or
ini_set('include_path', '');
However, neither one of these sets the include path to '' on the latest version of PHP 4
or PHP 5 in Linux.
A non-obvious workaround is to use a whitespace string:
set_include_path(' '); // or
ini_set('include_path', ' ');
which does set the path to ' ' (which hopefully isn't a valid directory!).
I believe passing a lambda string to either set_include_path or ini_set('include_path')
should set the path to the lambda string.
http://bytejar.com/ - Software Lessons Learned the Hard Way
Reproduce code:
---------------
$original_path = set_include_path('');
Expected result:
----------------
'' === get_include_path();
Actual result:
--------------
$original_path === get_include_path();
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=42517&edit=1