PHP 4.0 Bug #6999: dirname() returns empty string for "/foo/"

From: Date: Wed, 04 Oct 2000 02:20:11 +0000
Subject: PHP 4.0 Bug #6999: dirname() returns empty string for "/foo/"
Groups: php.dev 
Request: Send a blank email to php-dev+get-34157@lists.php.net to get a copy of this message
From: dolecek@ics.muni.cz Operating system: NetBSD 1.5G PHP version: 4.0.2 PHP Bug Type: *General Issues Bug description: dirname() returns empty string for "/foo/" echo dirname("/foo/"); prints nothing (or empty string). It should print "/foo". The problem is in way php_dirname() in ext/standad/string.c is handling trailing slashes. It strips all trailing slashes. Then it finds last no stripped slash (this leaves "/foo") and removes everything after last slash (this leaves empty string, ""). The code should be changed so that this speical case is treated correctly. Also, the code seems to access invalid memory if zero length string is passed (or do the PHP strings always have length at least one, containing '\0' ?). Anyway, the code there is potentially unsafe in case the memory before place with the string happens to contain slash. All three issues should be solved by following patch (not really tested, since I'm a bit time pressed at this moment, sorry). --- string.c.orig Tue Oct 3 15:52:12 2000 +++ string.c Tue Oct 3 16:04:02 2000 @@ -677,21 +677,22 @@ PHP_FUNCTION(basename) PHPAPI void php_dirname(char *str, int len) { register char *c; - c = str + len - 1; - while (*c == '/' -#ifdef PHP_WIN32 - || *c == '\\' -#endif - ) - c--; /* strip trailing slashes */ - *(c + 1) = '\0'; if ((c = strrchr(str, '/')) #ifdef PHP_WIN32 || (c = strrchr(str, '\\')) #endif - ) - *c='\0'; - else + ) { + + /* strip all trailing slashes, to properly handle cases + * like /path////foo or /path// + */ + while (c >= str && *c == '/' +#ifdef PHP_WIN32 + || *c == '\\' +#endif + ) c--; + *(c + 1) = '\0'; + } else *str='\0'; }

« previous php.dev (#34157) next »