Bug #77085 [Ver->Dup]: Function glob() is not checked for open_basedir
| From: | cmb@php.net | Date: | Mon, 02 Aug 2021 16:08:17 +0000 |
| Subject: | Bug #77085 [Ver->Dup]: Function glob() is not checked for open_basedir | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-235532@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77085&edit=1
ID: 77085
Updated by: cmb@php.net
Reported by: pavtov90 at gmail dot com
Summary: Function glob() is not checked for open_basedir
-Status: Verified
+Status: Duplicate
Type: Bug
Package: Filesystem function related
Operating System: Windows/Linux
PHP Version: 7.2.11
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Well, this is actually a duplicate of bug #65489.
Previous Comments:
------------------------------------------------------------------------
[2018-10-31 15:58:17] pavtov90 at gmail dot com
Getting a bypass on open_basedir?
------------------------------------------------------------------------
[2018-10-31 15:16:10] cmb@php.net
The open_basedir check is done for each of the globbed files, and
suppresses warnings[1], likely to prevent multiple warnings.
However, it doesn't trigger a single open_basedir related warning,
if an open_basedir violation had been detected[2].
> If false(no file or folder exists)
> Result : array(0){}
This is a particular issue. If no file is globbed, no individual
open_basedir check can be done (and possibly fail). While there
is a open_basedir check on the pattern[3], it is skipped on
Windows, and I wonder whether it can be sufficient for all
possible glob patterns on other systems.
To avoid any open_basedir related differences, we could never
return an empty array (and never raise an open_basedir warning),
but that would be quite a BC break[4].
BTW: the
continue[5] doesn't seem to make sense. A break
should be more sensible.
[1] <https://github.com/php/php-src/blob/php-7.3.0RC4/ext/standard/dir.c#L516>
[2] <https://github.com/php/php-src/blob/php-7.3.0RC4/ext/standard/dir.c#L546-L547>
[3] <https://github.com/php/php-src/blob/php-7.3.0RC4/ext/standard/dir.c#L504>
[4] <https://github.com/php/php-src/blob/php-7.3.0RC4/ext/standard/dir.c#L478-L484>
[5] <https://github.com/php/php-src/blob/php-7.3.0RC4/ext/standard/dir.c#L518>
------------------------------------------------------------------------
[2018-10-31 08:33:26] spam2 at rhsoft dot net
would you stop your one char comments triggering in mails leading to whatever cared about the
Bugreport filters it no?
------------------------------------------------------------------------
[2018-10-31 07:59:59] pavtov90 at gmail dot com
/
------------------------------------------------------------------------
[2018-10-31 02:25:43] pavtov90 at gmail dot com
on linux - PHP Version 7.1.23
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77085
--
Edit this bug report at https://bugs.php.net/bug.php?id=77085&edit=1