Bug #77085 [Opn->Ver]: Function glob() is not checked for open_basedir

From: Date: Wed, 31 Oct 2018 15:16:11 +0000
Subject: Bug #77085 [Opn->Ver]: Function glob() is not checked for open_basedir
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217771@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77085&edit=1 ID: 77085 Updated by: cmb@php.net Reported by: pavtov90 at gmail dot com Summary: Function glob() is not checked for open_basedir -Status: Open +Status: Verified Type: Bug -Package: *General Issues +Package: Filesystem function related Operating System: Windows/Linux PHP Version: 7.2.11 Block user comment: N Private report: N New Comment: The open_basedir check is done for each of the globbed files, and suppresses warnings[1], likely to prevent multiple warnings. However, it doesn't trigger a single open_basedir related warning, if an open_basedir violation had been detected[2]. > If false(no file or folder exists) > Result : array(0){} This is a particular issue. If no file is globbed, no individual open_basedir check can be done (and possibly fail). While there is a open_basedir check on the pattern[3], it is skipped on Windows, and I wonder whether it can be sufficient for all possible glob patterns on other systems. To avoid any open_basedir related differences, we could never return an empty array (and never raise an open_basedir warning), but that would be quite a BC break[4]. BTW: the continue[5] doesn't seem to make sense. A break should be more sensible. [1] <https://github.com/php/php-src/blob/php-7.3.0RC4/ext/standard/dir.c#L516> [2] <https://github.com/php/php-src/blob/php-7.3.0RC4/ext/standard/dir.c#L546-L547> [3] <https://github.com/php/php-src/blob/php-7.3.0RC4/ext/standard/dir.c#L504> [4] <https://github.com/php/php-src/blob/php-7.3.0RC4/ext/standard/dir.c#L478-L484> [5] <https://github.com/php/php-src/blob/php-7.3.0RC4/ext/standard/dir.c#L518> Previous Comments: ------------------------------------------------------------------------ [2018-10-31 08:33:26] spam2 at rhsoft dot net would you stop your one char comments triggering in mails leading to whatever cared about the Bugreport filters it no? ------------------------------------------------------------------------ [2018-10-31 07:59:59] pavtov90 at gmail dot com / ------------------------------------------------------------------------ [2018-10-31 02:25:43] pavtov90 at gmail dot com on linux - PHP Version 7.1.23 ------------------------------------------------------------------------ [2018-10-31 02:24:12] pavtov90 at gmail dot com . ------------------------------------------------------------------------ [2018-10-31 02:23:42] pavtov90 at gmail dot com I am testing in Linux through ini_set('open_basedir','/path/'); And he gave me the same result ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77085 -- Edit this bug report at https://bugs.php.net/bug.php?id=77085&edit=1

« previous php.bugs (#217771) next »