Bug #80457 [Opn]: stream_get_contents() fails with maxlength=-1 or default

From: Date: Tue, 01 Dec 2020 16:28:43 +0000
Subject: Bug #80457 [Opn]: stream_get_contents() fails with maxlength=-1 or default
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230774@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80457&edit=1

 ID:                 80457
 User updated by:    bruno dot premont at restena dot lu
 Reported by:        bruno dot premont at restena dot lu
 Summary:            stream_get_contents() fails with maxlength=-1 or
                     default
 Status:             Open
 Type:               Bug
 Package:            Filesystem function related
 Operating System:   Linux, x32
 PHP Version:        7.3.25
 Block user comment: N
 Private report:     N

 New Comment:

@cmb: If I had a public git repo I could offer a pull request, though I don't, thus the patch.

I didn't check if PHP-7.4.x or PHP-8 are affected too, but I guess they are.


Yes, X32 is a Linux ABI on x86_64.

What I was more surprised is about size_t and ssize_t being 32bit and not 64bit as plain x86_64
while off_t is 64bit.


Previous Comments:
------------------------------------------------------------------------
[2020-12-01 15:57:12] nikic@php.net

@cmb: Note that x32 != x86. x32 is a Linux ABI for ... x64.

------------------------------------------------------------------------
[2020-12-01 15:52:22] cmb@php.net

> Under X32 zend_long is 64bit […]

That shouldn't be the case.  What's the value of PHP_INT_SIZE on
that system?

That said, the patch looks good to me.  Care to provide a PR?

------------------------------------------------------------------------
[2020-12-01 15:28:30] bruno dot premont at restena dot lu

Description:
------------
The change introduced in commit 62dce97973436f1830b18304e7939a03b18d44ba (Require non-negative
length in stream_get_contents()) causes stream_get_contents() to fail if no maxlength is provided
and even if maxlength is explicitly provided as -1.


This also causes some stream tests to fail.


The cause of the failure is the mix of type conversions where parts are signed and parts are
unsigned.

Under X32 zend_long is 64bit but size_t and ssize_t seem not to be.

Thus
  zend_long maxlength = (ssize_t)PHP_STREAM_COPY_ALL;
will store -1
but
  maxlength == PHP_STREAM_COPY_ALL
will compare a signed and a unsigned value causing trouble due to extending unsigned 32bit
PHP_STREAM_COPY_ALL to a signed 64bit value.


Blindly converting between unsigned PHP_STREAM_COPY_ALL and signed zend_long is prone to trouble.


Other probably affected code:
  phar extension (passing zend_long to php_stream_copy_to_mem() which takes a size_t for maxlength
after eventually having assigned PHP_STREAM_COPY_ALL to the zend_long.




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80457&edit=1


Thread (5 messages)

« previous php.bugs (#230774) next »