Bug #65489 [Opn->Csd]: glob() basedir check is inconsistent
| From: | git@php.net | Date: | Tue, 02 Aug 2022 17:37:00 +0000 |
| Subject: | Bug #65489 [Opn->Csd]: glob() basedir check is inconsistent | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-242106@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65489&edit=1
ID: 65489
Updated by: git@php.net
Reported by: ab@php.net
Summary: glob() basedir check is inconsistent
-Status: Open
+Status: Closed
Type: Bug
Package: Filesystem function related
Operating System: irrelevant
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of bukka
Revision: https://github.com/php/php-src/commit/e5ab9f45d58245534020820072dc3c491679cc21
Log: Fix bug #65489: glob() basedir check is inconsistent
Previous Comments:
------------------------------------------------------------------------
[2021-08-02 16:08:17] cmb@php.net
Related To: Bug #77085
------------------------------------------------------------------------
[2013-08-21 06:41:21] ab@php.net
Here's also a pull request implementing GlobIterator where this topic was
discussed https://github.com/php/php-src/pull/398
------------------------------------------------------------------------
[2013-08-20 15:43:10] ab@php.net
Description:
------------
As documentation states
"Returns an array containing the matched files/directories, an empty array if no
file matched or FALSE on error."
whereby in case when internal glob() has returned NOMATCH, there's no reliable
way to do basedir check. As examples below illustrate, when the glob query is
complex, glob() returned NOMATCH and query is valid within basedir, it still
will return bool(false) to the userspace in the most cases.
If the result is empty, using php_check_open_basedir_ex() on the pattern will
work "somehow" only if it's a direct filesystem path or close to it, so
generally such check is senseless. Therefore what documentation states about
returning an empty array vs. false cannot be guaranteed.
The same misbehavior persists on windows with correspondingly modified queries.
Test script:
---------------
<?php
ini_set("open_basedir", "/etc");
/* found */
var_dump(glob("/etc"));
/* found given you're on debian :) */
var_dump(glob("/???/issue"));
/* basedir restriction */
var_dump(glob("/usr"));
/* basedir restriction, but that's a random result. PHP
doesnot really check /usr/nonono and /etc/nonono against basedir */
var_dump(glob("/{usr,etc}/nonono", GLOB_BRACE));
/* erroneous basedir restriction */
var_dump(glob("/[e]??/hey"));
/* erroroneous basedir restriction */
var_dump(glob("/???/absent"));
Expected result:
----------------
array(1) {
[0]=>
string(4) "/etc"
}
array(1) {
[0]=>
string(10) "/etc/issue"
}
bool(false)
bool(false)
array(0) {
}
array(0) {
}
Actual result:
--------------
array(1) {
[0]=>
string(4) "/etc"
}
array(1) {
[0]=>
string(10) "/etc/issue"
}
bool(false)
bool(false)
bool(false)
bool(false)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65489&edit=1