Skip to content

Commit bba11e6

Browse files
committed
Merge branch 'PHP-8.3' into PHP-8.4
* PHP-8.3: Preserve bare NUL access with open_basedir on Windows (#24158)
2 parents 09c3e73 + 6d7aa18 commit bba11e6

2 files changed

Lines changed: 65 additions & 0 deletions

File tree

‎main/fopen_wrappers.c‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -151,6 +151,14 @@ PHPAPI int php_check_specific_open_basedir(const char *basedir, const char *path
151151
size_t path_len;
152152
int nesting_level = 0;
153153

154+
#ifdef PHP_WIN32
155+
/* Preserve the working-directory permission check for bare NUL. */
156+
if ((strcasecmp(path, "NUL") == 0 || strcasecmp(path, "NUL:") == 0)
157+
&& php_check_specific_open_basedir(basedir, ".") == 0) {
158+
return 0;
159+
}
160+
#endif
161+
154162
/* Special case basedir==".": Use script-directory */
155163
if (strcmp(basedir, ".") || !VCWD_GETCWD(local_open_basedir, MAXPATHLEN)) {
156164
/* Else use the unmodified path */
Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
--TEST--
2+
GH-24148: Bare NUL remains usable with open_basedir on Windows
3+
--SKIPIF--
4+
<?php
5+
if (PHP_OS_FAMILY !== 'Windows') die('skip Windows only');
6+
if (!function_exists('proc_open')) die('skip proc_open unavailable');
7+
?>
8+
--INI--
9+
open_basedir=
10+
--FILE--
11+
<?php
12+
chdir(__DIR__);
13+
foreach ([
14+
'Directory allowed' => __DIR__,
15+
'Devices explicitly allowed' => __FILE__ . ';NUL;NUL:',
16+
'Only file allowed' => __FILE__,
17+
] as $label => $basedir) {
18+
echo "$label:\n";
19+
var_dump(ini_set('open_basedir', $basedir) !== false);
20+
foreach (['NUL', 'nul:'] as $name) {
21+
$stream = @fopen($name, 'c');
22+
var_dump(is_resource($stream));
23+
if (is_resource($stream)) {
24+
fclose($stream);
25+
}
26+
}
27+
$process = @proc_open('cmd /c exit 0', [
28+
['pipe', 'r'], ['file', 'NUL', 'w'], ['file', 'nul:', 'w'],
29+
], $pipes);
30+
if (is_resource($process)) {
31+
fclose($pipes[0]);
32+
var_dump(proc_close($process) === 0);
33+
} else {
34+
var_dump(false);
35+
}
36+
var_dump(file_get_contents(__FILE__) !== false);
37+
}
38+
?>
39+
--EXPECT--
40+
Directory allowed:
41+
bool(true)
42+
bool(true)
43+
bool(true)
44+
bool(true)
45+
bool(true)
46+
Devices explicitly allowed:
47+
bool(true)
48+
bool(true)
49+
bool(true)
50+
bool(true)
51+
bool(true)
52+
Only file allowed:
53+
bool(true)
54+
bool(false)
55+
bool(false)
56+
bool(false)
57+
bool(true)

0 commit comments

Comments
 (0)