Bug #80457 [Opn]: stream_get_contents() fails with maxlength=-1 or default

From: Date: Tue, 01 Dec 2020 15:52:22 +0000
Subject: Bug #80457 [Opn]: stream_get_contents() fails with maxlength=-1 or default
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230771@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80457&edit=1 ID: 80457 Updated by: cmb@php.net Reported by: bruno dot premont at restena dot lu Summary: stream_get_contents() fails with maxlength=-1 or default Status: Open Type: Bug Package: Filesystem function related Operating System: Linux, x32 PHP Version: 7.3.25 Block user comment: N Private report: N New Comment: > Under X32 zend_long is 64bit […] That shouldn't be the case. What's the value of PHP_INT_SIZE on that system? That said, the patch looks good to me. Care to provide a PR? Previous Comments: ------------------------------------------------------------------------ [2020-12-01 15:28:30] bruno dot premont at restena dot lu Description: ------------ The change introduced in commit 62dce97973436f1830b18304e7939a03b18d44ba (Require non-negative length in stream_get_contents()) causes stream_get_contents() to fail if no maxlength is provided and even if maxlength is explicitly provided as -1. This also causes some stream tests to fail. The cause of the failure is the mix of type conversions where parts are signed and parts are unsigned. Under X32 zend_long is 64bit but size_t and ssize_t seem not to be. Thus zend_long maxlength = (ssize_t)PHP_STREAM_COPY_ALL; will store -1 but maxlength == PHP_STREAM_COPY_ALL will compare a signed and a unsigned value causing trouble due to extending unsigned 32bit PHP_STREAM_COPY_ALL to a signed 64bit value. Blindly converting between unsigned PHP_STREAM_COPY_ALL and signed zend_long is prone to trouble. Other probably affected code: phar extension (passing zend_long to php_stream_copy_to_mem() which takes a size_t for maxlength after eventually having assigned PHP_STREAM_COPY_ALL to the zend_long. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80457&edit=1

« previous php.bugs (#230771) next »