Can open files using invalid paths
Open
Nobody has claimed this yet.
Bug
Category: Filesystem
Category: Streams
- Dominant language
- C
- Stars
- 40.4k
- Forks
- 8.2k
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 96
Description
Description
The path / /../ /../ /../ /../path/to/file is considered invalid by some file check functions:
<?php
is_file("/ /../ /../ /../ /../path/to/file"); // -> false
realpath("/ /../ /../ /../ /../path/to/file"); // -> false
filesize("/ /../ /../ /../ /../path/to/file"); // -> false
However, the path can actually be used to open /path/to/file :
<?php
echo file_get_contents("/ /../ /../ /../ /../path/to/file");
$res = fopen("/ /../ /../ /../ /../path/to/file", "r");
echo fread($res, 1024);
PHP Version
< 8.3
Operating System
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Reproduce the exact path from the issue and compare file_get_contents() and fopen() with is_file(), realpath(), and filesize(). No source files or tests are named, so first locate the PHP file-opening and path-validation entry points, then add coverage showing whether these APIs should handle the path consistently.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, php
- Domain
- backend
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100