Req #48111 [Opn->Wfx]: unlink() does not delete symlinks without a target if open_basedir is used

From: Date: Fri, 21 May 2021 12:05:48 +0000
Subject: Req #48111 [Opn->Wfx]: unlink() does not delete symlinks without a target if open_basedir is used
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233950@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=48111&edit=1

 ID:                 48111
 Updated by:         cmb@php.net
 Reported by:        simon at stienen dot name
 Summary:            unlink() does not delete symlinks without a target
                     if open_basedir is used
-Status:             Open
+Status:             Wont fix
 Type:               Feature/Change Request
 Package:            Safe Mode/open_basedir
 Operating System:   FreeBSD 7.1-RELEASE/amd64
 PHP Version:        5.2.9
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

> Ok, a possible solution would be to apply the open_basedir check
> to the parent directory instead of the file or the symlink itself.

Well, that would require special casing for unlinking symlinks,
which was rejected for bug #29145.


Previous Comments:
------------------------------------------------------------------------
[2010-02-14 20:27:03] antoine dot contal+bugs dot php dot net at gmail dot com

Same issue with PHP 5.2.11.

------------------------------------------------------------------------
[2009-04-29 20:39:06] simon at stienen dot name

Ok, a possible solution would be to apply the open_basedir check to the parent directory instead of
the file or the symlink itself.

I have implemented and slightly tested this, but please consider that my C knowledge is somewhat
limited and I have almost no insight into PHPs internals, so please treat these diffs with the
necessary care:

http://trashbin.slashlife.org/tmp/plain_wrapper.c.diff
http://trashbin.slashlife.org/tmp/plain_wrapper.c.-p.diff
http://trashbin.slashlife.org/tmp/plain_wrapper.c.-u.diff

------------------------------------------------------------------------
[2009-04-29 17:42:48] simon at stienen dot name

Description:
------------
unlink()ing a symlink with its target missing fails with an open_basedir error.

This might be related to
http://bugs.php.net/bug.php?id=20235 (actual
deletion changed, but sanitization still uses target?) and/or
http://bugs.php.net/bug.php?id=29145 (missing
target (empty string?) is considered to be outside of open_basedir?)


Reproduce code:
---------------
<?php

echo "creating link\n";
symlink('nonexisting_target', 'link');

echo "unlinking link\n";
unlink('link');

echo "creating target\n";
file_put_contents('nonexisting_target', 'foo');

echo "unlinking link (again)\n";
unlink('link');

echo "unlinking target\n";
unlink('nonexisting_target');


Expected result:
----------------
Run with php -d open_basedir=

creating link
unlinking link
creating target
unlinking link (again)

Warning: unlink(link): No such file or directory in /tmp/- on line 13
unlinking target


Actual result:
--------------
Run with php -d open_basedir=/

creating link
unlinking link

Warning: unlink(): open_basedir restriction in effect. File(link) is not within the allowed path(s):
(/) in /tmp/- on line 7
creating target
unlinking link (again)
unlinking target


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=48111&edit=1


Thread (5 messages)

« previous php.bugs (#233950) next »