Bug #78406 [Opn->Ver]: Broken file includes with user-defined stream filters
| From: | cmb@php.net | Date: | Tue, 13 Aug 2019 08:16:31 +0000 |
| Subject: | Bug #78406 [Opn->Ver]: Broken file includes with user-defined stream filters | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222212@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78406&edit=1
ID: 78406
Updated by: cmb@php.net
Reported by: lisachenko dot it at gmail dot com
Summary: Broken file includes with user-defined stream
filters
-Status: Open
+Status: Verified
Type: Bug
Package: Streams related
Operating System: Windows x64
PHP Version: 7.4.0beta2
Block user comment: N
Private report: N
New Comment:
This behavioral change has been introduced with commit c2c5c9a[1].
[1] <http://git.php.net/?p=php-src.git;a=commit;h=c2c5c9a973559b7ba9f84337c5f8078e59e98a91>
Previous Comments:
------------------------------------------------------------------------
[2019-08-12 17:08:52] lisachenko dot it at gmail dot com
Reproduced example: https://3v4l.org/jEMEE
------------------------------------------------------------------------
[2019-08-12 17:03:24] lisachenko dot it at gmail dot com
Description:
------------
Go! AOP framework heavily uses PHP file includes with applied stream filters like that:
include 'php://filter/read=sample.filter/resource=/some/path/to/php/file
In the latest version this inclusion with applied filter logic can result in a parse error like
this:
Parse error: syntax error, unexpected end of file
Test script:
---------------
<?php
echo 'bug'; // Should be transformed by filter on second include
if (!class_exists(SampleFilter::class)) {
class SampleFilter extends php_user_filter
{
private $data = '';
public function filter($in, $out, &$consumed, $closing)
{
while ($bucket = stream_bucket_make_writeable($in))
{
$this->data .= $bucket->data;
}
if ($closing || feof($this->stream))
{
$consumed = strlen($this->data);
$this->data = str_replace('bug', 'feature', $this->data);
$bucket = stream_bucket_new($this->stream, $this->data);
stream_bucket_append($out, $bucket);
return PSFS_PASS_ON;
}
return PSFS_FEED_ME;
}
}
stream_filter_register('sample.filter', SampleFilter::class);
$uri = 'php://filter/read=sample.filter/resource='. __FILE__;
$content = file_get_contents($uri);
echo '<pre>', htmlentities($content), '</pre>'; // Looks good
include $uri; // We expect one more "feature" output at line 3
}
Expected result:
----------------
bug
<?php
echo 'feature'; // Should be transformed by filter on second include
if (!class_exists(SampleFilter::class)) {
class SampleFilter extends php_user_filter
{
private $data = '';
public function filter($in, $out, &$consumed, $closing)
{
while ($bucket = stream_bucket_make_writeable($in))
{
$this->data .= $bucket->data;
}
if ($closing || feof($this->stream))
{
$consumed = strlen($this->data);
$this->data = str_replace('feature', 'feature',
$this->data);
$bucket = stream_bucket_new($this->stream, $this->data);
stream_bucket_append($out, $bucket);
return PSFS_PASS_ON;
}
return PSFS_FEED_ME;
}
}
stream_filter_register('sample.filter', SampleFilter::class);
$uri = 'php://filter/read=sample.filter/resource='. __FILE__;
$content = file_get_contents($uri);
echo '<pre>', htmlentities($content), '</pre>'; // Looks good
include $uri; // We expect one more "feature" output at line 3
}
feature
Actual result:
--------------
bug
<?php
echo 'feature'; // Should be transformed by filter on second include
if (!class_exists(SampleFilter::class)) {
class SampleFilter extends php_user_filter
{
private $data = '';
public function filter($in, $out, &$consumed, $closing)
{
while ($bucket = stream_bucket_make_writeable($in))
{
$this->data .= $bucket->data;
}
if ($closing || feof($this->stream))
{
$consumed = strlen($this->data);
$this->data = str_replace('feature', 'feature',
$this->data);
$bucket = stream_bucket_new($this->stream, $this->data);
stream_bucket_append($out, $bucket);
return PSFS_PASS_ON;
}
return PSFS_FEED_ME;
}
}
stream_filter_register('sample.filter', SampleFilter::class);
$uri = 'php://filter/read=sample.filter/resource='. __FILE__;
$content = file_get_contents($uri);
echo '<pre>', htmlentities($content), '</pre>'; // Looks good
include $uri; // We expect one more "feature" output at line 3
}
Parse error: syntax error, unexpected end of file in H:\Work\go\demos\stream.php on line 38
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78406&edit=1