Re: error_log binary unsafe

From: Date: Mon, 28 Oct 2013 11:45:23 +0000
Subject: Re: error_log binary unsafe
References: 1 2 3 4 5 6 7 8 9  Groups: php.internals 
Request: Send a blank email to internals+get-69913@lists.php.net to get a copy of this message
On 10/28/2013 11:42 AM, Julien Pauli wrote:
On Mon, Oct 28, 2013 at 12:11 PM, Joe Watkins <krakjoe@php.net> wrote:
On 10/28/2013 10:50 AM, Julien Pauli wrote:
On Sun, Oct 27, 2013 at 7:14 AM, Joe Watkins <pthreads@pthreads.org> wrote: On 10/26/2013 11:54 PM, Yasuo Ohgaki wrote:
Hi Joe,
On Sun, Oct 27, 2013 at 7:48 AM, Yasuo Ohgaki <yohgaki@ohgaki.net <mailto: yohgaki@ohgaki.net>> wrote:
      On Sat, Oct 26, 2013 at 2:38 PM, Joe Watkins
      <pthreads@pthreads.org <mailto:pthreads@pthreads.org>****> wrote:
          Mail is not yet handled, TCP/IP is not supported any more,
          streams are binary safe.
          The SAPI and default error logging mechanism are all that
          require attention.
          The patch is not final and doesn't include a fix for every
          implementation of SAPI.
          I don't see the need for confusion ??
      Generally speaking, I'm not against making functions/features
      binary safe.
      There are many implementations of syslog/SAPI and not sure if it
      is good for all.
      It could cause BC issue also. For example, application like OSSEC
      HIDS detects
      possible intrusion by analyzing logs. Patching SAPI may break
      these applications.
      I'm not against applying your patch to master, but it's not for
      released versions.
      We needs UPGRADE note if the patch is applied.
I think it's good for master. Do you have commit karma? If not, I'm willing to merge your patch unless there are not objections. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net <mailto:yohgaki@ohgaki.net>
I don't have karma ... There are lots of SAPI's, but this patch wasn't meant to implement them all, only to provide a route whereby they can implement binary safe log_message in the shape of log_message_ex. The patch implements binsafe log for cli and cgi, do we need to implement any more ??
Joe: Why do you use strlen() ? This leads to the same not binary safe string, am I wrong ?? https://github.com/krakjoe/**php-src/commit/** be5f38ddd449c20230c042aef9757e**fb2ee08188#diff-** 1a9cfc6173e3a434387996e46086da**56R610<https://github.com/krakjoe/php-src/commit/be5f38ddd449c20230c042aef9757efb2ee08188#diff-1a9cfc6173e3a434387996e46086da56R610> Julien Pauli
(sorry if you got this twice, my interweb is playing up) Hi Julien,
         The binary safe logging interface for SAPI is log_message_ex and
the binary safe logging function for php is php_log_err_ex
         The old function must remain, and use string length just as it did
before.
I see, that means that the actual patch does not turn logging to binary safe logs, but gives functions for that. Turning logs to binary safe would then mean tracking every unsafe log function (php_log_err()) and turn it to php_log_err_ex() with an explicit string length. Julien Pauli
http://lxr.php.net/search?q=&defs=&refs=php_log_err&path=&hist=&project=PHP_5_5 Not the enormous task you imagine it to be :) Cheers Joe

« previous php.internals (#69913) next »