Bug #78641 [Ver->Csd]: addGlob modifies value of constant when used in remove_path with trailing slash
| From: | cmb@php.net | Date: | Tue, 08 Oct 2019 07:51:39 +0000 |
| Subject: | Bug #78641 [Ver->Csd]: addGlob modifies value of constant when used in remove_path with trailing slash | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223129@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78641&edit=1
ID: 78641
Updated by: cmb@php.net
Reported by: support at hiorg-server dot de
Summary: addGlob modifies value of constant when used in
remove_path with trailing slash
-Status: Verified
+Status: Closed
Type: Bug
Package: Zip Related
Operating System: Debian GNU/Linux 10 (buster)
PHP Version: 7.3.10
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=fd3118ffb0a47d39489607967172c3b3fc75277a
Log: Fix #78641: addGlob can modify given remove_path value
Previous Comments:
------------------------------------------------------------------------
[2019-10-08 07:48:08] cmb@php.net
> Removing the trailing slash turned out to be a simple workaround
> for this issue.
You likely want to stick with this workaround, because bug #72374
will only be fixed as of PHP 8.0.0.
> This might imply that the bug changes the cached bytecode?
At least the attempt could be made.
------------------------------------------------------------------------
[2019-10-08 06:35:08] support at hiorg-server dot de
There is one more thing we would like to add: If the constant is defined in an include script this
bug can have a negative side effect for other scripts, too, if they depend on the same constant
which can lead to endless debugging sessions.
We found out that the value of the constant is invalid until the include script which defines the
constant will be modified (e.g. by calling "touch include.php"). This might imply that the
bug changes the cached bytecode?
------------------------------------------------------------------------
[2019-10-07 17:09:42] cmb@php.net
Indeed! Thanks for reporting.
------------------------------------------------------------------------
[2019-10-07 15:08:29] support at hiorg-server dot de
Description:
------------
After adding a file by addGlob using add_path and remove_path options, the value of the constant
used to define the "remove_path" has changed if it has a trailing slash.
Maybe the code block in line 1604/1605 of php-src/ext/zip/php_zip.c
(https://github.com/php/php-src/blob/4d6f88e2152888e4e4e8ac40c2d4a68d28b6a208/ext/zip/php_zip.c#L1604)
causes this bug since in these lines the "remove_path" will be modified.
Removing the trailing slash turned out to be a simple workaround for this issue.
I have used the following Dockerfile to build a docker container with php7.3.10 to reproduce this
bug.
FROM php:7.3.10-cli
RUN apt-get clean
RUN apt-get update
#install some base extensions
RUN apt-get install -y \
libzip-dev \
zip \
&& docker-php-ext-configure zip --with-libzip \
&& docker-php-ext-install zip
Test script:
---------------
<?php
define("TMPDIR", __DIR__ . "/");
$file = 'foo-bar';
touch($file);
$zip = new ZipArchive();
$zip->open("test.zip", ZipArchive::CREATE | ZipArchive::OVERWRITE);
var_dump(TMPDIR);
$zip->addGlob($file, 0, ["remove_path" => TMPDIR]);
var_dump(TMPDIR);
$zip->close();
Expected result:
----------------
string(15) "/usr/src/myapp/"
string(15) "/usr/src/myapp/"
Actual result:
--------------
string(15) "/usr/src/myapp/"
string(15) "/usr/src/myapp"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78641&edit=1