Doc #81179 [Ver->Csd]: fileperms() return wrong access information

From: Date: Mon, 21 Jun 2021 13:00:42 +0000
Subject: Doc #81179 [Ver->Csd]: fileperms() return wrong access information
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-18892@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81179&edit=1

 ID:                 81179
 Updated by:         git@php.net
 Reported by:        jhr at informedwebmaster dot com
 Summary:            fileperms() return wrong access information
-Status:             Verified
+Status:             Closed
 Type:               Documentation Problem
 Package:            *Directory/Filesystem functions
 Operating System:   Windows Server 2019 Ver.: 1809
 PHP Version:        8.0.7
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of cmb69
Revision: https://github.com/php/doc-en/commit/1f7d8b1ee9e6c7350857ddc8bfce248a65a29787
Log: Fix #81179: fileperms() return wrong access information


Previous Comments:
------------------------------------------------------------------------
[2021-06-21 12:41:13] cmb@php.net

Well, fileperms() calls stat() (actually, on Windows there is an
own implementation as of PHP 7.4.0, so MSVCRT stat() is no longer
called, but that doesn't matter n this regard), and that only
checks the file attributes, and if the read-only flag is set, it
reports that the file has no write permissions for *all* users
(i.e. you either get 0444 or 0666 for files, never e.g. 0644).

is_writable(), however, additionally does an AccessCheck()
according to the ACL, so reports whether the file is actually
writable by the (impersonated) user.

While this is inconsistent on Windows, it doesn't really make
sense to fix it, because file permissons are rather different to
POSIX.  We should, however, document this behavior.

------------------------------------------------------------------------
[2021-06-20 04:20:15] jhr at informedwebmaster dot com

Description:
------------
This bug can be reproduced by creating a directory called test in the root of drive C:, add an text
file in the directory named "test.txt", give the IUSR user read but not write access to
the file. IUSR is the user account php uses on IIS 10 when running php-scripts. Then runthe
following php-code:

echo substr(sprintf('%o', fileperms('C:\test\test.txt')), -4);

It will show "0666" even thou the current user does not have write permission to the file.
If it's helpful, is_writable('C:\test\test.txt') does correctly return false.

Test script:
---------------
I did not write this code, i found it on php.net. But it works fine to reproduce the bug(please read
description):

echo substr(sprintf('%o', fileperms('C:\test\test.txt')), -4);

Expected result:
----------------
I expected to see "0644".

Actual result:
--------------
Actual result was "0666".


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81179&edit=1


Thread (2 messages)

« previous php.doc.bugs (#18892) next »