Req #42517 [Fbk->NoF]: set_include_path('') doesn't work as expected

From: Date: Sun, 24 Jun 2018 04:22:22 +0000
Subject: Req #42517 [Fbk->NoF]: set_include_path('') doesn't work as expected
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215887@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=42517&edit=1 ID: 42517 Updated by: php-bugs@lists.php.net Reported by: php at ideacode dot com Summary: set_include_path('') doesn't work as expected -Status: Feedback +Status: No Feedback Type: Feature/Change Request Package: *General Issues Operating System: Linux PHP Version: 5.2.4 Private report: N New Comment: No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. Previous Comments: ------------------------------------------------------------------------ [2018-05-05 18:54:22] requinix@php.net Even with the include_path cleared, absolute and CWD-relative paths will continue to work. I'm not sure how forcing developers to use such a path, like one as simple as __DIR__."/a/b/c.php", adds security to places where path information is not already unknown. Is there still any interest in this? Can someone give more details about a problem this would solve? ------------------------------------------------------------------------ [2017-07-25 21:28:05] powtac at gmx dot de 1. It seems that only setting at least 1 char "clears" the include_path. This can be tested with checking the (bool) result. Example: set_include_path(' '); 2. It seems that after setting or "unsetting" the include_path still ".:.." is active as path where PHP searches for files. ------------------------------------------------------------------------ [2007-09-02 00:20:51] php at ideacode dot com Description: ------------ There are legitimate "secure-operation" situations when you want the include path wiped out, so that all included files must be explicitly stated. The obvious way to set this is with either: set_include_path(''); // or ini_set('include_path', ''); However, neither one of these sets the include path to '' on the latest version of PHP 4 or PHP 5 in Linux. A non-obvious workaround is to use a whitespace string: set_include_path(' '); // or ini_set('include_path', ' '); which does set the path to ' ' (which hopefully isn't a valid directory!). I believe passing a lambda string to either set_include_path or ini_set('include_path') should set the path to the lambda string. http://bytejar.com/ - Software Lessons Learned the Hard Way Reproduce code: --------------- $original_path = set_include_path(''); Expected result: ---------------- '' === get_include_path(); Actual result: -------------- $original_path === get_include_path(); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=42517&edit=1

« previous php.bugs (#215887) next »