Bug #71263 [Ver->Csd]: fread() does not report bzip2.decompress errors
Edit report at https://bugs.php.net/bug.php?id=71263&edit=1
ID: 71263
Updated by: cmb@php.net
Reported by: salsi at icosaedro dot it
Summary: fread() does not report bzip2.decompress errors
-Status: Verified
+Status: Closed
Type: Bug
Package: Streams related
Operating System: Slackware 14.1
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=d757be640f5105b8542b781ce93804af494229a8
Log: Fix #71263: fread() does not report bzip2.decompress errors
Previous Comments:
------------------------------------------------------------------------
[2020-04-17 13:39:43] cmb@php.net
> The zlib.inflate filter has the same issue.
But that has already reported as bug #71417.
------------------------------------------------------------------------
[2020-04-17 13:37:02] cmb@php.net
The zlib.inflate filter has the same issue.
------------------------------------------------------------------------
[2020-04-17 12:13:03] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #71263: fread() does not report bzip2.decompress errors
On GitHub: https://github.com/php/php-src/pull/5406
Patch: https://github.com/php/php-src/pull/5406.patch
------------------------------------------------------------------------
[2020-04-17 08:35:41] cmb@php.net
As of PHP 7.4.0, bzip2.decompress errors already cause fread() to
return false, due to a more general fix of the stream behavior[1].
This is still a silent failure, though.
[1] <https://www.php.net/manual/en/migration74.incompatible.php#migration74.incompatible.core.fread-fwrite>
------------------------------------------------------------------------
[2016-01-16 00:27:04] salsi at icosaedro dot it
Possibly related:
1. require* and include* do not detect input/output error
https://bugs.php.net/bug.php?id=71385
2. fread() does not detect file access error
https://bugs.php.net/bug.php?id=71384
In all these case it seems I/O errors fails to propagate through the chain of the stream functions,
either returning empty string or garbage, with severe safety and security risks both for front-end
and back-end processes.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71263
--
Edit this bug report at https://bugs.php.net/bug.php?id=71263&edit=1
Thread (7 messages)