Bug #77656 [Opn]: proc_open() ignores invalid cwd argument

From: Date: Mon, 18 Mar 2019 13:38:08 +0000
Subject: Bug #77656 [Opn]: proc_open() ignores invalid cwd argument
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220043@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77656&edit=1 ID: 77656 User updated by: php at yghe dot net Reported by: php at yghe dot net Summary: proc_open() ignores invalid cwd argument Status: Open Type: Bug Package: Program Execution Operating System: Mac OS X 10.14.3 PHP Version: 7.3.2 Block user comment: N Private report: N New Comment: Yes, you're correct. A better "expected result" is perhaps: The subprocess exits immediately with an error code after "chdir()" fails, instead of executing in the wrong working directory. Before this, optionally, "proc_open()" might make some attempt to validate the directory and fail early with a more specific error message if "chdir()" seems unlikely to succeed (for example, because the working directory does not exist). However, this might be a difficult test to perform in the general case -- perhaps there are cases under, say, SELinux, where the parent process may be unable to see or access the directory but the child can. Previous Comments: ------------------------------------------------------------------------ [2019-03-18 10:57:05] nikic@php.net From a quick look, the problem here is that chdir() is called after forking, at which point we can no longer influence whether proc_open in the parent process succeeds or not. ------------------------------------------------------------------------ [2019-02-22 22:41:06] php at yghe dot net Description: ------------ If the "$cwd" argument to "proc_open()" is invalid, the problem is ignored and execution continues (usually, with the wrong working directory). In "proc_open.c", near line 835, the return value of "chdir()" is explicitly ignored: https://github.com/php/php-src/commit/a5eeecb13f8683eaadb137aee33ac2dd292bf1fc#diff-19f692ed5f75687fc7bc1929910e540f Test script: --------------- <?php $spec = array( 0 => array('pipe', 'r'), 1 => array('pipe', 'w'), 2 => array('pipe', 'w') ); $pipes = array(); $proc = proc_open( 'pwd', $spec, $pipes, 'asldknfaeqwglknewqklnwnrfl'); // <<< Any Invalid Directory var_dump($proc); var_dump(stream_get_contents($pipes[1])); var_dump(proc_get_status($proc)); Expected result: ---------------- "proc_open()" fails to open a subprocess and returns false if the "$cwd" argument is provided but not valid. Actual result: -------------- "proc_open()" continues in the presence of an invalid "$cwd", likely executing the subprocess in the wrong working directory. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77656&edit=1

« previous php.bugs (#220043) next »