Bug #70362 [Ver->Csd]: Can't copy() large 'data://' with open_basedir
| From: | cmb@php.net | Date: | Tue, 30 Jun 2020 08:49:49 +0000 |
| Subject: | Bug #70362 [Ver->Csd]: Can't copy() large 'data://' with open_basedir | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227734@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70362&edit=1
ID: 70362
Updated by: cmb@php.net
Reported by: prochazkapp at gmail dot com
Summary: Can't copy() large 'data://' with open_basedir
-Status: Verified
+Status: Closed
Type: Bug
Package: Filesystem function related
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=7f3bc64287588f6a838d1a9524624deba1e5e153
Log: Fix #70362: Can't copy() large 'data://' with open_basedir
Previous Comments:
------------------------------------------------------------------------
[2020-03-05 11:29:36] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #70362: Can't copy() large 'data://' with open_basedir
On GitHub: https://github.com/php/php-src/pull/5237
Patch: https://github.com/php/php-src/pull/5237.patch
------------------------------------------------------------------------
[2015-08-26 16:04:20] prochazkapp at gmail dot com
Description:
------------
If open_basedir is enabled, 'data://' wrapper does not work correctly with copy() for data
bigger than MAXPATHLEN.
I found this bug in php 5.5.21 but it affects all versions (even 7).
See https://3v4l.org/5h1aI
Here is why:
copy() calls php_check_open_basedir
https://github.com/php/php-src/blob/PHP-5.5.21/ext/standard/file.c#L1618
And this checks source len end trigger error.
https://github.com/php/php-src/blob/PHP-5.5.21/main/fopen_wrappers.c#L303
But source len is not relevant for e.g. 'data://' wrapper (and possible some other
wrappers).
This seems fixed in some other file functions:
https://github.com/php/php-src/blob/PHP-5.5.21/ext/standard/filestat.c#L867
If data:// wrapper is not intended to work with copy, it should be mentioned in docs, but function
works otherwise perfectly with disabled open_basedir or for smaller data.
This may be related to https://bugs.php.net/bug.php?id=60456 but I believe
it's not duplicate.
Test script:
---------------
<?php
ini_set('open_basedir', '/');
$temp = tempnam(__DIR__, 'test');
$data = str_repeat('0', PHP_MAXPATHLEN * 2);
$data = 'data://plain/text;base64,' . base64_encode($data);
var_dump(copy($data, $temp));
Expected result:
----------------
bool(true)
Actual result:
--------------
Warning: copy(): File name is longer than the maximum allowed path length on this platform (4096):
data:plain/text;base64,... in ... on line 6
bool(false)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70362&edit=1