PHP 4.0 Bug #6376: File in include_path is run instead of file in DocumentRoot

From: Date: Sun, 27 Aug 2000 13:14:39 +0000
Subject: PHP 4.0 Bug #6376: File in include_path is run instead of file in DocumentRoot
Groups: php.dev 
Request: Send a blank email to php-dev+get-30813@lists.php.net to get a copy of this message
From: rwidmer@developersdesk.com Operating system: Linux SuSe 6.3 PHP version: 4.0 Latest CVS (27/08/2000) PHP Bug Type: Scripting Engine problem Bug description: File in include_path is run instead of file in DocumentRoot This was actually found with www.php.net/~andi/php-4.0.2RC1.tar.gz compiled as a static apache module. With RC1 the include_path can override the program being executed. As late as 200007300345 it did not. Also, when PHP encounters a directory in the path with the same name as the currently executing program it fails with: Fatal error: input in flex scanner failed in /web/hosts/www.southernidahojobs.com/phplib/pre/test.php on line 1 It took a while to figure out that PHP is taking the name of the program being executed (the URL from the browser) and searching the include_path for it. I believe that it should always execute the program in DocumentRoot like it has before. Although I first saw the problem with a conflicting directory, I have found it is also triggered by conflicting file names. To see it you need a file or directory in the include path, before ./ with the same name as the script you are executing. For example: in some config file php_value include_path /path/to/includes:./:/more/paths in DocumentRoot test.php: ------------------------- <? phpinfo(); ?> ------------------------- in /path/to/includes/ test.php: ------------------------- hello from the path! ------------------------- Now hit http://www.somedomain.com/test.php and you get: hello from the path! At least I do. If you move test.php from /path/to/includes to /more/paths it will work properly. (After the ./ in the include_path) This is on the new (6.3) SuSe machine using apache 1.3.12, mod-ssl 2.6.5, openssl 0.9.5a and RC1 or the 07/30 shapshot all freshly compiled from tarballs. (I started by rm'ing the source directories, of apache, mod_ssl and php4 so it should have been a clean compile.) I get the same error on port 80 and port 443. Also, if you go to the /path/to/includes directory and: rm test.php mkdir test.php Now you should get: Fatal error: input in flex scanner failed in /web/hosts/www.southernidahojobs.com/phplib/pre/test.php on line 1 This is probably not too unreasonable, but I had to take a break after a couple hours trying to track it down before I could figure out that it was a matter of pointing php at a directory rather than a file. Without the include_path bug I don't think you could possibly get here if you hit a directory with apache it handles it before deciding to call php. I hope I am not the only one who can see this one... ./configure options... php4: /configure --with-mysql=../mysql \ --with-apache=../apache \ --with-config-file-path=/web/conf --enable-track-vars apache: SSL_BASE=../openssl \ /configure --prefix=/usr/local/apache \ --enable-module=ssl \ --enable-module=info \ --enable-module=rewrite \ --enable-module=log_referer \ --disable-module=userdir \ --activate-module=src/modules/php4/phplib4.a \ --enable-module=php4

« previous php.dev (#30813) next »