#48719 [Asn]: parse_ini_file scanner more sanitation

[email protected] ("dragoonis at gmail dot com")
Newsgroups php.bugs
Message-ID <[email protected]>
 ID:               48719
 User updated by:  dragoonis at gmail dot com
 Reported By:      dragoonis at gmail dot com
 Status:           Assigned
 Bug Type:         *General Issues
 Operating System: *
 PHP Version:      5.3.0RC4
 Assigned To:      kalle
 New Comment:

After more learning of how things work i've made the ZendEngine2 .patch
file and uploaded it to the following location.
http://digiflexdev.com/php/48719.patch


Previous Comments:
------------------------------------------------------------------------

[2009-06-29 13:44:40] dragoonis at gmail dot com

Firstly, the original reproduce code has a syntax error in it however
heres what happens if you pass a valid constant to the function which
isn't ZEND_INI_SCANNER_NORMAL and ZEND_INI_SCANNER_RAW

<?php
error_reporting(E_ALL);
defie('MODE', 3);
print_r(parse_ini_file('file.ini', false, MODE));


The fix outputs the following.
Notice: parse_ini_file(): Invalid scanner mode supplied. Defaulting to
INI_SCANNER_NORMAL in /home/pdragoonis/php-5.3.0/sapi/cli/file.php on
line 5
Array
(
    [data] => 2
)

------------------------------------------------------------------------

[2009-06-29 13:15:59] dragoonis at gmail dot com

Changed OS to 'All'

------------------------------------------------------------------------

[2009-06-29 13:13:02] dragoonis at gmail dot com

Description:
------------
The sanitation on the new parse_ini_file parameter names scanner mode
doesn't check if a valid scanner mode has been passed.

The patch has been applied below the if() for if (filename_len == 0)
{.
The fix can be found here:
http://digiflexdev.com/php/parse_ini_file_fix.txt

The .phpt file for this is below
http://digiflexdev.com/php/parse_ini_file_test.txt
I realise the .phpt file is wrong somewhat this is my first bug report
and the .phpt file just shows.

The same issue applies to parse_ini_string, respectively.

Reproduce code:
---------------
<?php print_r(parse_ini_file('file.ini', false',
INVALID_SCANNER_MODE));

Make a file named file.ini with the following in it.
data = 2

Expected result:
----------------
I'd expect to see a notice. and default to ZEND_INI_SCANNER_NORMAL
which is what my fix does.

Actual result:
--------------
Warning: parse_ini_file() expects parameter 3 to be long, string given
in /home/pdragoonis/php-5.3.0/sapi/cli/pd/parse_ini_file_test.php on
line 3


------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=48719&edit=1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.