Bug #77561 [Opn->Csd]: Shebang line not stripped for non-primary script
| From: | nikic@php.net | Date: | Mon, 10 Aug 2020 08:40:22 +0000 |
| Subject: | Bug #77561 [Opn->Csd]: Shebang line not stripped for non-primary script | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-228479@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77561&edit=1
ID: 77561
Updated by: nikic@php.net
Reported by: sebastian@php.net
Summary: Shebang line not stripped for non-primary script
-Status: Open
+Status: Closed
Type: Bug
Package: Scripting Engine problem
Operating System: Irrelevant
PHP Version: 7.3.1
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=896dad4c794f7826812bcfdbaaa9f0b3518d9385
Log: Fixed bug #77561
Previous Comments:
------------------------------------------------------------------------
[2020-08-10 08:36:19] nikic@php.net
I'm going to enable unconditional stripping of the shebang line for the CLI SAPI in PHP 8.0. I
think there is very little chance that someone intentionally want to preserve a shebang line when
including a PHP file that starts with one, and this does regularly cause issues when scripts are
reused in multiple contexts.
------------------------------------------------------------------------
[2019-07-15 14:46:18] nikic@php.net
Based on https://github.com/php/php-src/commit/c5f1b384b591009310370f0b06b10868d2d62741
it would now be (technically) easy to always strip shebang lines, though I'm not sure whether
we should do actually do it.
------------------------------------------------------------------------
[2019-02-05 16:28:22] spam2 at rhsoft dot net
yeah that would solve this problem, in the example below 'auth.php' is a NOOP in case
PHP_SAPI === 'cli' and when called from the webserver it verifies the userlogin and stops
with a loginform
that's in fact a cronjob file and the web-call is for "i need that damned task now and not
in 5 minutes" and i have dozens of examples where this makes sense
#!/usr/bin/php
<?php declare(strict_types=1);
require __DIR__ . '/../../auth.php';
$cl_api->worker->import();
?>
------------------------------------------------------------------------
[2019-02-05 16:10:04] nikic@php.net
I just looked into this a bit. Shebang lines are currently handled by the SAPI layer, by stripping
it off before it even reaches the lexer. The CLI SAPI always does this, while the CGI SAPI has a
default-enabled ini option for it (cgi.check_shebang_line), that I learned about today. Other SAPIs
don't have this option.
I think we'll want to move the shebang stripping into the lexer, but I'm not sure if we
can get away with unconditionally enabling it.
------------------------------------------------------------------------
[2019-02-04 00:20:59] spam2 at rhsoft dot net
but for cli scripts exists an inconsistent hack für shebangs and the way it works makes it as
example imposible write a strict-typed script which works with different SAPI's
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77561
--
Edit this bug report at https://bugs.php.net/bug.php?id=77561&edit=1