Re: error_log binary unsafe
| From: | Yasuo Ohgaki | Date: | Sun, 27 Oct 2013 09:24:54 +0000 |
| Subject: | Re: error_log binary unsafe | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-69891@lists.php.net to get a copy of this message | ||
Hi Joe,
On Sun, Oct 27, 2013 at 4:40 PM, Joe Watkins <krakjoe@php.net> wrote:
> On 10/27/2013 07:33 AM, Yasuo Ohgaki wrote:
>
>> On Sun, Oct 27, 2013 at 3:14 PM, Joe Watkins <pthreads@pthreads.org>
>> wrote:
>>
>> The patch implements binsafe log for cli and cgi, do we need to implement
>>> any more ??
>>>
>>
>>
>> It's better to check & fix all SAPIs :)
>>
>> Regards,
>>
>> --
>> Yasuo Ohgaki
>> yohgaki@ohgaki.net
>>
>> Indeed ...
>
> But the original question I asked was for approval on the approach ...
>
> I guess I got that ??
>
> I don't mind implementing other SAPI's at all, I was just wondering if the
> approach is satisfactory ...
I think approach is ok.
We should leave receiver how the special characters are treated. Even if
receiver has problem with null chars, the result is merely a 'truncated
message' for most cases.
However, I should mention that some database systems (e.g. Oracle) just
ignore null char and it enables SQL injection detection bypass. (i.e.
application firewall bypass) Some databases would not accept null char as
valid text and refuse to store data. I would say this is not our issue, but
it's a kind of BC issue.
There may be many developers against your patch. I would suggest to create
RFC before start working on other SAPIs.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net