Bug #79072 [Asn->Nab]: If passed via a stream processor, the included file contents get corrupted

From: Date: Mon, 26 Jul 2021 22:33:27 +0000
Subject: Bug #79072 [Asn->Nab]: If passed via a stream processor, the included file contents get corrupted
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235384@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79072&edit=1 ID: 79072 Updated by: cmb@php.net Reported by: morozov at tut dot by Summary: If passed via a stream processor, the included file contents get corrupted -Status: Assigned +Status: Not a bug Type: Bug Package: Streams related Operating System: Linux PHP Version: 7.4.1 Assigned To: cmb Block user comment: N Private report: N New Comment: > Here's the actual patch: > https://github.com/php-vcr/php-vcr/pull/293 Okay, so this is more like not-a-bug (since the userland code should never have reported an invalid stat size. > You mean how it's implemented in 7.4? Yes (and this is also how its implemented in PHP 8). Previous Comments: ------------------------------------------------------------------------ [2021-07-26 22:17:44] morozov at tut dot by > It seems the original issue has been resolved, hasn't it? Yes, it's been resolved by changing the PHP code. Here's the actual patch: https://github.com/php-vcr/php-vcr/pull/293 > Yeah, but I think we [...] have to leave implementation as is until next major at least. You mean how it's implemented in 7.4? In this case, I agree. ------------------------------------------------------------------------ [2021-07-26 21:31:46] cmb@php.net It seems the original issue has been resolved, hasn't it? > Looking at the code, it treats any non-array return value as the > stat failing... Yeah, but I think we should leave documentation as is, and have to leave implementation as is until next major at least. ------------------------------------------------------------------------ [2020-01-17 11:56:56] nikic@php.net > You suggested to return false from stream_stat(), however the documentation says it should > return an array. Is it safe to return false and be sure the return type of > array won't be strictly enforced in a future PHP version? > Returning an empty array seems to work as well. Looking at the code, it treats any non-array return value as the stat failing... ------------------------------------------------------------------------ [2020-01-06 22:30:54] morozov at tut dot by > Your stream filter solution should also work fine though as long as you return false from > stream_stat() (or explicitly adjust the length). Thank you for the recommendation. It worked. The approach of using a temporary stream seems to be not that easy to integrate into the existing code of php-vcr since its API designed around using php_user_filters while in your example the entire file content is processed at once (although it indeed looks like a more reasonable approach for processing included files). You suggested to return false from stream_stat(), however the documentation says it should return an array. Is it safe to return false and be sure the return type of array won't be strictly enforced in a future PHP version? Returning an empty array seems to work as well. ------------------------------------------------------------------------ [2020-01-06 20:02:26] nikic@php.net > How can this be done? Removing either of the stream_stat() and url_stat() methods from the > stream wrapper makes PHP unable to include the file: You can do this by returning false from stream_stat(). You'll likely only want to do that if the stream was opened for include. > Not sure I understand the suggestion. The purpose of this code is to register a file:// > protocol handler that would change the file contents on the fly w/o having to modify the code that > includes or reads those files. How does simply open a php://temp stream solve this problem? It so happens that I've recently been dealing with on-the-fly include transforms as well, and the solution I adopted looks like this: https://github.com/nikic/include-interceptor/blob/8cffd8f75212eed30cbeaaf8ee8749d1b88d5c7f/src/Interceptor.php#L44-L47 That is, the transformed file contents are written to a php://temp stream (php://memory would probably also work) and that is then used as the file resource in the stream wrapper. Your stream filter solution should also work fine though as long as you return false from stream_stat() (or explicitly adjust the length). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79072 -- Edit this bug report at https://bugs.php.net/bug.php?id=79072&edit=1

« previous php.bugs (#235384) next »