Bug #69536 [Fbk->NoF]: Extracted ZipArchive archives have insecure permissions when extracted by OSX
| From: | php-bugs at lists dot php dot net | Date: | Sun, 29 Mar 2020 04:22:08 +0000 |
| Subject: | Bug #69536 [Fbk->NoF]: Extracted ZipArchive archives have insecure permissions when extracted by OSX | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-226312@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69536&edit=1
ID: 69536
Updated by: php-bugs@lists.php.net
Reported by: kevin dot cupp at ellislab dot com
Summary: Extracted ZipArchive archives have insecure
permissions when extracted by OSX
-Status: Feedback
+Status: No Feedback
Type: Bug
Package: Zip Related
Operating System: OSX
PHP Version: 5.5.24
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2020-03-18 13:00:38] remi@php.net
this is not a PHP/zip issue, rather a libzip one.
ZIP format is inherited from the old MS-DOS time and thus don't really manage permissions.
Some stuff is possible using the external attributes, but this is OS dependant, and raise
portability issues.
extractTo document have been amended to raise user attention about umask usage.
setExternalAttributesName documentation has an example how to save permissions
getExternalAttributesIndex documentation has an example how to restore permissions.
------------------------------------------------------------------------
[2019-07-09 02:06:26] requinix@php.net
> It looks like zip archives are very good compared to Tar archives.
Probably related to how TARs are uncompressed.
------------------------------------------------------------------------
[2019-07-09 02:04:42] peter dot achutha at gmail dot com
I compressed my website today with 3 different compression methods are below are the results:-
drpeterscode-20190709-0944.tar Tar Archive 491.18MB 100.00%
drpeterscode-20190709-0944.tar.gz GZiped Tar Archive 358.05MB 72.89%
drpeterscode-20190709-0944.zip Zip Archive 367.13MB 74.74%
It looks like zip archives are very good compared to Tar archives. The Zip archive was only 2.47%
bigger than the GZipped Tar Archive which is a negligible amount.
Furthermore, I ran gtmetrix.com test on the speed of my webpages under PHP 7.3 and PHP 5.5 and there
was no difference in speed.
Please upgrade zip archives so that it will work correctly in all versions of PHP from 5.5 to 7.3.
------------------------------------------------------------------------
[2019-02-23 01:03:57] peter dot achutha at gmail dot com
I have written about this on my blog, http://drpetersnews.com/php-zip-archive-not-working-apache-server-hard-disk-full-problems.php,
as I really like using zip.
I do hope the authorities will restore PHP zip archives to work with all versions of PHP, from 5.5
to 7.3.
------------------------------------------------------------------------
[2019-02-22 08:16:53] peter dot achutha at gmail dot com
I ran another test on the PHP zip archive issue. I found that, with PHP 5.5 all file permissions are
set to 0644. It does not matter whether the original file permissions were set to 0666 or 0444 or
any other value. When you unzip the file the the permissions will be set to 0644.
I then tested this with PHP 5.6 and tried to zip and unzip files whose permissions were 0644 or
0444. When unzipped their permissions where set to 0666.
Further testing showed that the file permissions were set at the point of compression and not during
unzipping. As I unzipped a file under PHP 5.6, that was zipped under PHP 5.5, and it unzipped with
file permission of 0644. When I unzipped a file under PHP 5.5 that was zipped under PHP 5.6 the file
permission were set to 0666. It did not matter what the original permissions were.
This clearly shows that the PHP zip archive function does not check the file or directory
permissions when zipping files. It just defaults them to 0644 or 0666. Why?
Why did the developers not check the file permissions for the files being compressed and use those
values? fileperms()? Can't we specify what permission we want the directories and files to be?
For example:-
$zipArchive->addFile('atestzip.php', 'atestzip.php', 0644);
By doing this, we can write a PHP script to check every file's permission and set the
permission before adding it to be compressed. If the permission is not set then a default setting
can be used.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69536
--
Edit this bug report at https://bugs.php.net/bug.php?id=69536&edit=1