Bug #79296 [Com]: ZipArchive::open fails on empty file (libzip 1.6.0)

From: Date: Thu, 19 Mar 2020 16:39:02 +0000
Subject: Bug #79296 [Com]: ZipArchive::open fails on empty file (libzip 1.6.0)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226184@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79296&edit=1

 ID:                 79296
 Comment by:         remi@php.net
 Reported by:        dunglas at gmail dot com
 Summary:            ZipArchive::open fails on empty file (libzip 1.6.0)
 Status:             Feedback
 Type:               Bug
 Package:            Zip Related
 Operating System:   Mac OS X
 PHP Version:        7.4.3
 Block user comment: N
 Private report:     N

 New Comment:

BTW, if I still don't know if we should fixed this issue, a possible mitigation is proposed in
linked PR.


Previous Comments:
------------------------------------------------------------------------
[2020-03-19 16:38:08] remi@php.net

The following pull request has been associated:

Patch Name: Fix Bug #79296 ZipArchive::open fails on empty file
On GitHub:  https://github.com/php/php-src/pull/5281
Patch:      https://github.com/php/php-src/pull/5281.patch

------------------------------------------------------------------------
[2020-03-19 13:30:12] remi@php.net

This is not a change in PHP nor ZIP extension, but in libzip 1.6.0, from Changelog

* Do not accept empty files as valid zip archives any longer.


So indeed your code have to be adapted.


I propose to close as "not a bug"

------------------------------------------------------------------------
[2020-03-10 15:20:59] dv dot sum0 at gmail dot com

We saw the same issue on a Centos 7 machine, changed between 7.4.2 and 7.4.3

It seems to be caused by the fact that the tempnam() function creates an empty file immediately, if
you use a different filename that doesn't already exist it works as expected.

------------------------------------------------------------------------
[2020-02-22 11:10:57] dunglas at gmail dot com

Description:
------------
Creating a Zip archive in the default temporary directory of Mac OS doesn't work with Mac OS
Catalina.

Using the default TMPDIR to store temporary Zip archive, is a common practice. For instance
it's what PHP WebDriver does by default to create a temporary Firefox profile.

Using the OVERWRITE flag of libzip instead of the CREATE one fixes the problem.
This may be due do to the new security features introduced in Mac OS Catalina.

Tested with PHP 7.4 and 8.0-dev, but this bug probably affects all versions.

Test script:
---------------
<?php

$f = tempnam(sys_get_temp_dir(), 'WebDriverFirefoxProfileZip');


$zip = new ZipArchive();
$success = $zip->open($f, ZipArchive::CREATE);
// this work
// $success = $zip->open($f, ZipArchive::OVERWRITE);
if ($success !== true) {
    die('Error code '.$success);
}
$zip->addFile(__DIR__.'/foo.txt', '/foo.txt');
$zip->close();


Expected result:
----------------
No errors

Actual result:
--------------
Error 19

#define ZIP_ER_NOZIP 19           /* N Not a zip archive */



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=79296&edit=1


Thread (8 messages)

« previous php.bugs (#226184) next »