Bug #77656 [NEW]: proc_open() ignores invalid cwd argument

From: Date: Fri, 22 Feb 2019 22:41:06 +0000
Subject: Bug #77656 [NEW]: proc_open() ignores invalid cwd argument
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219710@lists.php.net to get a copy of this message
From: php at yghe dot net Operating system: Mac OS X 10.14.3 PHP version: 7.3.2 Package: Program Execution Bug Type: Bug Bug description:proc_open() ignores invalid cwd argument Description: ------------ If the "$cwd" argument to "proc_open()" is invalid, the problem is ignored and execution continues (usually, with the wrong working directory). In "proc_open.c", near line 835, the return value of "chdir()" is explicitly ignored: https://github.com/php/php-src/commit/a5eeecb13f8683eaadb137aee33ac2dd292bf1fc#diff-19f692ed5f75687fc7bc1929910e540f Test script: --------------- <?php $spec = array( 0 => array('pipe', 'r'), 1 => array('pipe', 'w'), 2 => array('pipe', 'w') ); $pipes = array(); $proc = proc_open( 'pwd', $spec, $pipes, 'asldknfaeqwglknewqklnwnrfl'); // <<< Any Invalid Directory var_dump($proc); var_dump(stream_get_contents($pipes[1])); var_dump(proc_get_status($proc)); Expected result: ---------------- "proc_open()" fails to open a subprocess and returns false if the "$cwd" argument is provided but not valid. Actual result: -------------- "proc_open()" continues in the presence of an invalid "$cwd", likely executing the subprocess in the wrong working directory. -- Edit bug report at https://bugs.php.net/bug.php?id=77656&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77656&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77656&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77656&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=77656&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=77656&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=77656&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=77656&r=needscript Try newer version: https://bugs.php.net/fix.php?id=77656&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=77656&r=support Expected behavior: https://bugs.php.net/fix.php?id=77656&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=77656&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=77656&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=77656&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77656&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=77656&r=dst IIS Stability: https://bugs.php.net/fix.php?id=77656&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=77656&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=77656&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=77656&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=77656&r=mysqlcfg

« previous php.bugs (#219710) next »