Bug #64634 [PATCH]: copy() not working with stream wrappers when open_basedir is set

From: Date: Tue, 12 May 2020 13:21:39 +0000
Subject: Bug #64634 [PATCH]: copy() not working with stream wrappers when open_basedir is set
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227011@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64634&edit=1 ID: 64634 Patch added by: alvin79.torre@gmail.com Reported by: ovidiu at softped dot com Summary: copy() not working with stream wrappers when open_basedir is set Status: Closed Type: Bug Package: Safe Mode/open_basedir Operating System: Windows PHP Version: 5.4.14 Assigned To: ab Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: Add php7 compatibility On GitHub: https://github.com/php/pecl-event-libevent/pull/2 Patch: https://github.com/php/pecl-event-libevent/pull/2.patch Previous Comments: ------------------------------------------------------------------------ [2020-05-12 13:16:55] alvin79 dot torre at gmail dot com The following pull request has been associated: Patch Name: WIP: Prepare 2.x branch On GitHub: https://github.com/php/pecl-php-uploadprogress/pull/5 Patch: https://github.com/php/pecl-php-uploadprogress/pull/5.patch ------------------------------------------------------------------------ [2014-01-05 20:20:29] ab@php.net Ok then, better not to touch the running system :) ------------------------------------------------------------------------ [2013-04-20 18:56:17] ovidiu at softped dot net I was actually using fread / fwrite because I didn't know about stream_copy_to_stream() but I will it instead. Thank you. ------------------------------------------------------------------------ [2013-04-19 08:31:50] ab@php.net Looks like the explicit basedir check can be removed in copy() as in the subsequential stack it calls _php_stream_open_wrapper_ex which would care about it anyway. Though I'm not sure what BC and security breaches it would introduce. @ovidiu what prevents you to use something like stream_copy_to_stream() or alike? ------------------------------------------------------------------------ [2013-04-11 19:14:40] ovidiu at softped dot com Description: ------------ When open_basedir is set to something other than "no value" the copy function fails when trying to read from php://input with the following message: Warning: copy(): open_basedir restriction in effect. File(php://input) is not within the allowed path(s): (d:\server) However, when trying file_get_contents('php://input') it successfully reads the data. Test script: --------------- <?php copy('php://input','destination.txt'); ?> Expected result: ---------------- Expected a new file to be created "destination.txt" with the contents of php://input Actual result: -------------- Warning: copy(): open_basedir restriction in effect. File(php://input) is not within the allowed path(s): (d:\server) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=64634&edit=1

« previous php.bugs (#227011) next »