Req #42517 [Fbk->NoF]: set_include_path('') doesn't work as expected
| From: | php-bugs at lists dot php dot net | Date: | Sun, 24 Jun 2018 04:22:22 +0000 |
| Subject: | Req #42517 [Fbk->NoF]: set_include_path('') doesn't work as expected | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215887@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=42517&edit=1
ID: 42517
Updated by: php-bugs@lists.php.net
Reported by: php at ideacode dot com
Summary: set_include_path('') doesn't work as expected
-Status: Feedback
+Status: No Feedback
Type: Feature/Change Request
Package: *General Issues
Operating System: Linux
PHP Version: 5.2.4
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2018-05-05 18:54:22] requinix@php.net
Even with the include_path cleared, absolute and CWD-relative paths will continue to work. I'm
not sure how forcing developers to use such a path, like one as simple as
__DIR__."/a/b/c.php", adds security to places where path information is not already
unknown.
Is there still any interest in this? Can someone give more details about a problem this would solve?
------------------------------------------------------------------------
[2017-07-25 21:28:05] powtac at gmx dot de
1. It seems that only setting at least 1 char "clears" the include_path. This can be
tested with checking the (bool) result. Example: set_include_path(' ');
2. It seems that after setting or "unsetting" the include_path still ".:.." is
active as path where PHP searches for files.
------------------------------------------------------------------------
[2007-09-02 00:20:51] php at ideacode dot com
Description:
------------
There are legitimate "secure-operation" situations when you want the include path wiped
out, so that all included files must be explicitly stated.
The obvious way to set this is with either:
set_include_path(''); // or
ini_set('include_path', '');
However, neither one of these sets the include path to '' on the latest version of PHP 4
or PHP 5 in Linux.
A non-obvious workaround is to use a whitespace string:
set_include_path(' '); // or
ini_set('include_path', ' ');
which does set the path to ' ' (which hopefully isn't a valid directory!).
I believe passing a lambda string to either set_include_path or ini_set('include_path')
should set the path to the lambda string.
http://bytejar.com/ - Software Lessons Learned the Hard Way
Reproduce code:
---------------
$original_path = set_include_path('');
Expected result:
----------------
'' === get_include_path();
Actual result:
--------------
$original_path === get_include_path();
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=42517&edit=1