Re: error_log binary unsafe

From: Date: Sun, 27 Oct 2013 09:24:54 +0000
Subject: Re: error_log binary unsafe
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to internals+get-69891@lists.php.net to get a copy of this message
Hi Joe, On Sun, Oct 27, 2013 at 4:40 PM, Joe Watkins <krakjoe@php.net> wrote: > On 10/27/2013 07:33 AM, Yasuo Ohgaki wrote: > >> On Sun, Oct 27, 2013 at 3:14 PM, Joe Watkins <pthreads@pthreads.org> >> wrote: >> >> The patch implements binsafe log for cli and cgi, do we need to implement >>> any more ?? >>> >> >> >> It's better to check & fix all SAPIs :) >> >> Regards, >> >> -- >> Yasuo Ohgaki >> yohgaki@ohgaki.net >> >> Indeed ... > > But the original question I asked was for approval on the approach ... > > I guess I got that ?? > > I don't mind implementing other SAPI's at all, I was just wondering if the > approach is satisfactory ... I think approach is ok. We should leave receiver how the special characters are treated. Even if receiver has problem with null chars, the result is merely a 'truncated message' for most cases. However, I should mention that some database systems (e.g. Oracle) just ignore null char and it enables SQL injection detection bypass. (i.e. application firewall bypass) Some databases would not accept null char as valid text and refuse to store data. I would say this is not our issue, but it's a kind of BC issue. There may be many developers against your patch. I would suggest to create RFC before start working on other SAPIs. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#69891) next »