Bug #73048 [Ver->Nab]: scandir() does not work without permission to parent folder.

From: Date: Mon, 28 Jun 2021 13:56:27 +0000
Subject: Bug #73048 [Ver->Nab]: scandir() does not work without permission to parent folder.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234663@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73048&edit=1

 ID:                 73048
 Updated by:         cmb@php.net
 Reported by:        aj at ajhenderson dot com
 Summary:            scandir() does not work without permission to parent
                     folder.
-Status:             Verified
+Status:             Not a bug
 Type:               Bug
 Package:            Directory function related
 Operating System:   Windows
 PHP Version:        7.0.10
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Time flies …

> Do you have anyone else listed there?

Right.  If I remove these as well, I can reproduce.

However, this is actually expected behavior (and not particularly
Windows related); all file and directory functions call
realpath(3) (actually PHP's own implementation), and that requires
permission to access all path components.


Previous Comments:
------------------------------------------------------------------------
[2016-09-10 06:15:46] requinix@php.net

Interesting. I tried 7.0.10 (NTS x64) on Win10 Pro 10586.

Add a
  passthru("icacls parent");
to the end of the setup block: I get as output
  parent NT AUTHORITY\SYSTEM:(OI)(CI)(F)
         BUILTIN\Administrators:(OI)(CI)(F)

Do you have anyone else listed there? That could be a difference between Home and Pro - or just a
difference in our setups, of course.

Speaking of, I'm logged in as a domain user who is supposedly part of the local Administrators
group.


Anyway, Process Monitor shows only a failed CreateFile for parent:

High Resolution Date & Time:	2016-09-09 22:44:21.3795403
Event Class:	File System
Operation:	CreateFile
Result:	ACCESS DENIED
Path:	...\parent
TID:	8444
Duration:	0.0000311
Desired Access:	Read Data/List Directory, Synchronize
Disposition:	Open
Options:	Directory, Synchronous IO Non-Alert
Attributes:	n/a
ShareMode:	Read, Write, Delete
AllocationSize:	n/a

Watching cmd, dir parent\child does a CreateFile directly on child.

------------------------------------------------------------------------
[2016-09-09 23:48:59] cmb@php.net

Thanks for the reproduce script, Damian!

I can't, however, reproduce scandir() failing with PHP 7.0.10 on
Windows 10 Home build 10586.545; instead running the script
produces the output in
<https://gist.github.com/cmb69/eae8211716b11aee2576b5041d07e004>.
Apparently, the permissions are set as intended, as dir parent
confirms ("Datei nicht gefunden"), while dir parent\child lists
the folder contents.

------------------------------------------------------------------------
[2016-09-08 17:25:18] requinix@php.net

When testing, remember that NTFS has permission inheritance.
1. Create parent and child directories
2. Edit permissions on both to disable inheritance (and replace with existing inherited permissions)
3. Remove permissions on parent folder

Commands like dir (dir parent\child) are able to display the contents of the child
directory, however commands like attrib (attrib parent\child) rightfully do not work.
It'd be easy to say that PHP's behavior is intentional/not a bug, however if dir can do it
then I'd think PHP should be able to as well.

<?php

// setup
mkdir("parent") && mkdir("parent\\child") &&
touch("parent\\child\\file.txt");
passthru("icacls parent /inheritance:d"); // so we can remove this user's perms
passthru("icacls parent\\child /inheritance:d"); // so it doesn't inherit
parent's perms
passthru("icacls parent /remove %USERNAME%");

// works
passthru("dir parent\\child");

// does not work
print_r(scandir("parent\\child"));

// cleanup
passthru("icacls parent /grant %USERNAME%:f");
unlink("parent\\child\\file.txt") && rmdir("parent\\child") &&
rmdir("parent");

?>

------------------------------------------------------------------------
[2016-09-08 15:08:06] aj at ajhenderson dot com

Description:
------------
When attempting to scandir() on a folder which the user has permission to, it fails with Access is
Denied (code 5) if the user does not have access to the parent directory as well.

Expected result:
----------------
Scandir should be able to scan the folder that the PHP user has permission to access.

Actual result:
--------------
Access is denied (code 5) returned.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73048&edit=1


Thread (5 messages)

« previous php.bugs (#234663) next »