Bug #75708 [PATCH]: getimagesize with "&$imageinfo" fails on StreamWrappers

From: Date: Sun, 15 Oct 2023 15:58:19 +0000
Subject: Bug #75708 [PATCH]: getimagesize with "&$imageinfo" fails on StreamWrappers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-245579@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75708&edit=1

 ID:                 75708
 Patch added by:     bukka@php.net
 Reported by:        joehoyle at gmail dot com
 Summary:            getimagesize with "&$imageinfo" fails on
                     StreamWrappers
 Status:             Verified
 Type:               Bug
 Package:            Streams related
 Operating System:   Alpine Linux
 PHP Version:        7.1.12
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

The following pull request has been associated:

Patch Name: Fix bug #75708: getimagesize with "&$imageinfo" fails on StreamWrappers
On GitHub:  https://github.com/php/php-src/pull/12444
Patch:      https://github.com/php/php-src/pull/12444.patch


Previous Comments:
------------------------------------------------------------------------
[2023-09-23 20:41:49] bukka@php.net

I have spent quite a bit of time on this today and the reason is that stream wrapper does not use
greedy reading so not the whole length is returned if the chunk is read full. This happens only for
some images so I will need to figure the pattern out as I'm able to recreate only for really
big images which is not convenient for test addition. Otherwise I have got a fix in https://github.com/bukka/php-src/commit/88a8095a20c6598cdf6e3ce0b2a6849fb58c5a8b
but need to finish the test as I said.

The whole stream handling seems a bit incomplete as even with var it does not check seek return
value which is not probably right. The whole handling needs more looking and investigation and some
follow up fixes are likely.

------------------------------------------------------------------------
[2018-06-22 14:23:28] requinix@php.net

Related To: Bug #76521

------------------------------------------------------------------------
[2017-12-20 16:18:55] cmb@php.net

I can confirm the erroneous behavior.  Interestingly, calling
getimagesize() without the second parameter succeeds without
warnings.  The only relevant difference is that the info parameter
causes php_read_APP() to be called, while without info parameter
php_skip_variable() is called[1].  However, the relevant
difference between php_skip_variable()[2] and php_read_APP()[3] is
that the former calls php_stream_seek() while the latter calls
php_stream_read() (both with the same offset/length).  Apparently,
there is an issue regarding php_stream_read(); possibly related to
bug #72561.

[1] <https://github.com/php/php-src/blob/PHP-7.2.0/ext/standard/image.c#L535-L543>
[2] <https://github.com/php/php-src/blob/PHP-7.2.0/ext/standard/image.c#L424-L437>
[3] <https://github.com/php/php-src/blob/PHP-7.2.0/ext/standard/image.c#L439-L471>

------------------------------------------------------------------------
[2017-12-20 02:54:34] joehoyle at gmail dot com

Description:
------------
When using getimagesize( $path, $imageinfo ) on specific images in conjunction with a custom
StreamWrapper path, multiple "PHP Warning:  getimagesize(): corrupt JPEG data: 536 extraneous
bytes before marker in..." errors are shown, and the $imageinfo is empty.

This also happens with a "fake filesystem streamwrapper" as demonstrated.

Test script:
---------------
https://gist.github.com/joehoyle/b9484e6375ce3a1d4cbefe5e439ef80d

Using image: https://joehoyle-captured.s3.amazonaws.com/test.jpg

Expected result:
----------------
bool(true)
bool(true)
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 183 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 140 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 175 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 854 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 723 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 31 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 79 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 502 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 48 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 116 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 295 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 710 extraneous bytes
before marker in /usr/src/app/test.php on line 60
[20-Dec-2017 02:51:20 UTC] PHP Warning:  getimagesize(): corrupt JPEG data: 536 extraneous bytes
before marker in /usr/src/app/test.php on line 60
done

Actual result:
--------------
bool(true)
bool(true)
done


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=75708&edit=1


Thread (7 messages)

« previous php.bugs (#245579) next »