Re: error_log binary unsafe
| From: | Joe Watkins | Date: | Mon, 28 Oct 2013 11:45:23 +0000 |
| Subject: | Re: error_log binary unsafe | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-69913@lists.php.net to get a copy of this message | ||
On 10/28/2013 11:42 AM, Julien Pauli wrote:
On Mon, Oct 28, 2013 at 12:11 PM, Joe Watkins <krakjoe@php.net> wrote:http://lxr.php.net/search?q=&defs=&refs=php_log_err&path=&hist=&project=PHP_5_5 Not the enormous task you imagine it to be :) Cheers JoeOn 10/28/2013 10:50 AM, Julien Pauli wrote:I see, that means that the actual patch does not turn logging to binary safe logs, but gives functions for that. Turning logs to binary safe would then mean tracking every unsafe log function (php_log_err()) and turn it to php_log_err_ex() with an explicit string length. Julien PauliOn Sun, Oct 27, 2013 at 7:14 AM, Joe Watkins <pthreads@pthreads.org> wrote: On 10/26/2013 11:54 PM, Yasuo Ohgaki wrote:(sorry if you got this twice, my interweb is playing up) Hi Julien,Hi Joe,Joe: Why do you use strlen() ? This leads to the same not binary safe string, am I wrong ?? https://github.com/krakjoe/**php-src/commit/** be5f38ddd449c20230c042aef9757e**fb2ee08188#diff-** 1a9cfc6173e3a434387996e46086da**56R610<https://github.com/krakjoe/php-src/commit/be5f38ddd449c20230c042aef9757efb2ee08188#diff-1a9cfc6173e3a434387996e46086da56R610> Julien PauliOn Sun, Oct 27, 2013 at 7:48 AM, Yasuo Ohgaki <yohgaki@ohgaki.net <mailto: yohgaki@ohgaki.net>> wrote:I don't have karma ... There are lots of SAPI's, but this patch wasn't meant to implement them all, only to provide a route whereby they can implement binary safe log_message in the shape of log_message_ex. The patch implements binsafe log for cli and cgi, do we need to implement any more ??On Sat, Oct 26, 2013 at 2:38 PM, Joe Watkins<pthreads@pthreads.org <mailto:pthreads@pthreads.org>****> wrote:Mail is not yet handled, TCP/IP is not supported any more, streams are binary safe. The SAPI and default error logging mechanism are all that require attention.The patch is not final and doesn't include a fix for every implementation of SAPI.I don't see the need for confusion ??Generally speaking, I'm not against making functions/features binary safe.There are many implementations of syslog/SAPI and not sure if it is good for all. It could cause BC issue also. For example, application like OSSEC HIDS detects possible intrusion by analyzing logs. Patching SAPI may break these applications.I'm not against applying your patch to master, but it's not for released versions. We needs UPGRADE note if the patch is applied.I think it's good for master. Do you have commit karma? If not, I'm willing to merge your patch unless there are not objections. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net <mailto:yohgaki@ohgaki.net>The binary safe logging interface for SAPI is log_message_ex andthe binary safe logging function for php is php_log_err_exThe old function must remain, and use string length just as it didbefore.