Bug #74252 [Asn->Wfx]: Non-existent STDIN duplicates FD 0 instead of registering it as closed stream

From: Date: Tue, 17 Sep 2019 15:30:52 +0000
Subject: Bug #74252 [Asn->Wfx]: Non-existent STDIN duplicates FD 0 instead of registering it as closed stream
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222789@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74252&edit=1 ID: 74252 Updated by: nikic@php.net Reported by: kelunik@php.net Summary: Non-existent STDIN duplicates FD 0 instead of registering it as closed stream -Status: Assigned +Status: Wont fix Type: Bug Package: Streams related Operating System: Linux PHP Version: Irrelevant Assigned To: nikic Block user comment: N Private report: N New Comment: I've tried to address this in https://github.com/php/php-src/pull/4685, but failed because stdin already get hijacked prior to main(). I think the only thing left to say here is that closed stdio streams are ill-defined (UB in C), and you should be piping /dev/null instead. Previous Comments: ------------------------------------------------------------------------ [2019-09-06 12:30:27] nikic@php.net The following pull request has been associated: Patch Name: Handle closed stdio streams On GitHub: https://github.com/php/php-src/pull/4685 Patch: https://github.com/php/php-src/pull/4685.patch ------------------------------------------------------------------------ [2017-03-16 11:55:51] kelunik@php.net In fact, /dev/urandom is opened by some extension. With ./configure --disable-all PHP segfaults with the same test case. $ sapi/cli/php -r 'var_dump(!!fstat(STDIN));passthru("ls -o /proc/".getmypid()."/fd");' <&- bool(false) insgesamt 0 lr-x------ 1 kelunik 64 Mär 16 12:51 0 -> pipe:[7290202] lrwx------ 1 kelunik 64 Mär 16 12:51 1 -> /dev/pts/1 lrwx------ 1 kelunik 64 Mär 16 12:51 2 -> /dev/pts/1 Speicherzugriffsfehler (Speicherabzug geschrieben) ------------------------------------------------------------------------ [2017-03-15 14:55:28] kelunik@php.net Description: ------------ If no STDIN exists, STDIN is still registered as FD 0 instead of a closed stream. This results in scripts without STDIN reading from /dev/urandom, because that's opened and just uses the next free FD. Instead of duplicating the FD in https://github.com/php/php-src/blob/16ae9f82e82e2aea5d7deaf8f9a9c825a56dfcc1/ext/standard/php_fopen_wrapper.c#L265 it should be registered as closed stream. See also https://github.com/reactphp/stream/issues/81. Test script: --------------- php -r 'var_dump(!!fstat(STDIN));passthru("ls -o /proc/".getmypid()."/fd");' <&- Expected result: ---------------- STDIN should be a closed stream instead of /dev/urandom Actual result: -------------- STDIN is /dev/urandom ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74252&edit=1

« previous php.bugs (#222789) next »