Bug #77561 [Opn->Csd]: Shebang line not stripped for non-primary script

From: Date: Mon, 10 Aug 2020 08:40:22 +0000
Subject: Bug #77561 [Opn->Csd]: Shebang line not stripped for non-primary script
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-228479@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77561&edit=1 ID: 77561 Updated by: nikic@php.net Reported by: sebastian@php.net Summary: Shebang line not stripped for non-primary script -Status: Open +Status: Closed Type: Bug Package: Scripting Engine problem Operating System: Irrelevant PHP Version: 7.3.1 Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=896dad4c794f7826812bcfdbaaa9f0b3518d9385 Log: Fixed bug #77561 Previous Comments: ------------------------------------------------------------------------ [2020-08-10 08:36:19] nikic@php.net I'm going to enable unconditional stripping of the shebang line for the CLI SAPI in PHP 8.0. I think there is very little chance that someone intentionally want to preserve a shebang line when including a PHP file that starts with one, and this does regularly cause issues when scripts are reused in multiple contexts. ------------------------------------------------------------------------ [2019-07-15 14:46:18] nikic@php.net Based on https://github.com/php/php-src/commit/c5f1b384b591009310370f0b06b10868d2d62741 it would now be (technically) easy to always strip shebang lines, though I'm not sure whether we should do actually do it. ------------------------------------------------------------------------ [2019-02-05 16:28:22] spam2 at rhsoft dot net yeah that would solve this problem, in the example below 'auth.php' is a NOOP in case PHP_SAPI === 'cli' and when called from the webserver it verifies the userlogin and stops with a loginform that's in fact a cronjob file and the web-call is for "i need that damned task now and not in 5 minutes" and i have dozens of examples where this makes sense #!/usr/bin/php <?php declare(strict_types=1); require __DIR__ . '/../../auth.php'; $cl_api->worker->import(); ?> ------------------------------------------------------------------------ [2019-02-05 16:10:04] nikic@php.net I just looked into this a bit. Shebang lines are currently handled by the SAPI layer, by stripping it off before it even reaches the lexer. The CLI SAPI always does this, while the CGI SAPI has a default-enabled ini option for it (cgi.check_shebang_line), that I learned about today. Other SAPIs don't have this option. I think we'll want to move the shebang stripping into the lexer, but I'm not sure if we can get away with unconditionally enabling it. ------------------------------------------------------------------------ [2019-02-04 00:20:59] spam2 at rhsoft dot net but for cli scripts exists an inconsistent hack für shebangs and the way it works makes it as example imposible write a strict-typed script which works with different SAPI's ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77561 -- Edit this bug report at https://bugs.php.net/bug.php?id=77561&edit=1

« previous php.bugs (#228479) next »