PHP 4.0 Bug #6999: dirname() returns empty string for "/foo/"
| From: | dolecek at ics dot muni dot cz | Date: | Wed, 04 Oct 2000 02:20:11 +0000 |
| Subject: | PHP 4.0 Bug #6999: dirname() returns empty string for "/foo/" | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-34157@lists.php.net to get a copy of this message | ||
From: dolecek@ics.muni.cz
Operating system: NetBSD 1.5G
PHP version: 4.0.2
PHP Bug Type: *General Issues
Bug description: dirname() returns empty string for "/foo/"
echo dirname("/foo/");
prints nothing (or empty string). It should print
"/foo".
The problem is in way php_dirname() in ext/standad/string.c
is handling trailing slashes. It strips all
trailing slashes. Then it finds last no stripped
slash (this leaves "/foo") and removes everything
after last slash (this leaves empty string, "").
The code should be changed so that this speical case
is treated correctly.
Also, the code seems to access invalid memory
if zero length string is passed (or do the PHP
strings always have length at least one, containing
'\0' ?). Anyway, the code there is potentially
unsafe in case the memory before place with the
string happens to contain slash.
All three issues should be solved by following patch
(not really tested, since I'm a bit time pressed at
this moment, sorry).
--- string.c.orig Tue Oct 3 15:52:12 2000
+++ string.c Tue Oct 3 16:04:02 2000
@@ -677,21 +677,22 @@ PHP_FUNCTION(basename)
PHPAPI void php_dirname(char *str, int len) {
register char *c;
- c = str + len - 1;
- while (*c == '/'
-#ifdef PHP_WIN32
- || *c == '\\'
-#endif
- )
- c--; /* strip trailing slashes */
- *(c + 1) = '\0';
if ((c = strrchr(str, '/'))
#ifdef PHP_WIN32
|| (c = strrchr(str, '\\'))
#endif
- )
- *c='\0';
- else
+ ) {
+
+ /* strip all trailing slashes, to properly handle cases
+ * like /path////foo or /path//
+ */
+ while (c >= str && *c == '/'
+#ifdef PHP_WIN32
+ || *c == '\\'
+#endif
+ ) c--;
+ *(c + 1) = '\0';
+ } else
*str='\0';
}