Bug #71385 [Opn]: require* and include* do not detect input/output error

From: Date: Wed, 05 Oct 2022 17:53:21 +0000
Subject: Bug #71385 [Opn]: require* and include* do not detect input/output error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242531@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71385&edit=1

 ID:                 71385
 Updated by:         bukka@php.net
 Reported by:        salsi at icosaedro dot it
 Summary:            require* and include* do not detect input/output
                     error
 Status:             Open
 Type:               Bug
-Package:            *Directory/Filesystem functions
+Package:            Streams related
 Operating System:   Slackware 14.1
 PHP Version:        master-Git-2016-01-16 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

Sorry it actually does as it uses php_fopen_wrapper_for_zend which uses
php_stream_open_wrapper_as_file ...


Previous Comments:
------------------------------------------------------------------------
[2022-10-05 17:45:30] bukka@php.net

This is not related to streams as require is not using them.

------------------------------------------------------------------------
[2016-01-16 00:06:38] salsi at icosaedro dot it

Description:
------------
Possibly related: fread() does not detect file access error (https://bugs.php.net/bug.php?id=71384).

Trying to include an unreadable file, the require* and include* family of statements do not to
detect the problem; no error nor exception whatsoever.

The simplest way to simulate an unreadable file on Linux is to read /proc/self/mem, a file that can
be successfully opened but cannot be read from the very beginning (credits for this trick: http://unix.stackexchange.com/a/6302):

	$ cat /proc/self/mem
	cat: /proc/self/mem: Input/output error

A simple test made with gcc C confirms that fopen() succeeds while fread() gives input/output error.

Under PHP, instead, no errors are detected, and that file can be "required", as the
following test script proves. Since "requiring" a file means that the code that follows
depends on it, there might be also safety and security profiles involved.



Test script:
---------------
<?php
echo "PHP version: ", PHP_VERSION, "\n";
// set safe test environment:
error_reporting(-1);
ini_set("track_errors", "1");

// maps errors to ErrorException:
function my_error_handler($errno, $message) {
	throw new ErrorException($message);
}
set_error_handler("my_error_handler");

define("UNREADABLE", "/proc/self/mem");
require UNREADABLE;
//require_once UNREADABLE;
//include UNREADABLE;
//include_once UNREADABLE;

echo "Just testing if error detection is still on:\n";
require "this file does not exist!";
?>

Expected result:
----------------
PHP version: 7.1.0-dev
(exception on the first fread() telling the file is unreadable)

Actual result:
--------------
PHP version: 7.1.0-dev
Just testing if error detection is still on:
PHP Warning:  Uncaught ErrorException: require(this file does not exist!): failed to open stream: No
such file or directory in /home/salsi/src/phplint/bug-require-unreadable-file.php:9
Stack trace:
#0 /home/salsi/src/phplint/bug-require-unreadable-file.php(20): my_error_handler(2,
'require(this fi...', '/home/salsi/src...', 20, Array)
#1 /home/salsi/src/phplint/bug-require-unreadable-file.php(20): require()
#2 {main}
  thrown in /home/salsi/src/phplint/bug-require-unreadable-file.php on line 9
Warning: Uncaught ErrorException: require(this file does not exist!): failed to open stream: No such
file or directory in /home/salsi/src/phplint/bug-require-unreadable-file.php:9
Stack trace:
#0 /home/salsi/src/phplint/bug-require-unreadable-file.php(20): my_error_handler(2,
'require(this fi...', '/home/salsi/src...', 20, Array)
#1 /home/salsi/src/phplint/bug-require-unreadable-file.php(20): require()
#2 {main}
  thrown in /home/salsi/src/phplint/bug-require-unreadable-file.php on line 9
PHP Fatal error:  main(): Failed opening required 'this file does not exist!'
(include_path='.') in /home/salsi/src/phplint/bug-require-unreadable-file.php on line 20
Fatal error: main(): Failed opening required 'this file does not exist!'
(include_path='.') in /home/salsi/src/phplint/bug-require-unreadable-file.php on line 20

(puzzled by this error message displayed twice, but this is not the subject of this issue anyway,
any suggestion appreciated :-)




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71385&edit=1


Thread (4 messages)

« previous php.bugs (#242531) next »