forked from php/php-src
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Fix #80329: Add option to specify LOAD DATA LOCAL white list folder
* allow the user to specify a folder where files that can be sent via LOAD DATA LOCAL can exist * add mysqli.local_infile_directory for mysqli (ignored if mysqli.allow_local_infile is enabled) * add PDO::MYSQL_ATTR_LOCAL_INFILE_DIRECTORY for pdo_mysql (ignored if PDO::MYSQL_ATTR_LOCAL_INFILE is enabled) * add related tests * fixes for building with libmysql 8.x * small improvement in existing tests * update php.ini-[development|production] files Closes phpGH-6448. Co-authored-by: Nikita Popov <[email protected]>
- Loading branch information
1 parent
7f8ea83
commit da011a3
Showing
40 changed files
with
743 additions
and
26 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
97 | ||
98 | ||
99 |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
1 | ||
2 | ||
3 |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
75 changes: 75 additions & 0 deletions
75
ext/mysqli/tests/mysqli_allow_local_infile_overrides_local_infile_directory.phpt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,75 @@ | ||
--TEST-- | ||
mysqli.allow_local_infile overrides mysqli.local_infile_directory | ||
--SKIPIF-- | ||
<?php | ||
require_once('skipif.inc'); | ||
require_once('skipifconnectfailure.inc'); | ||
|
||
if (!$link = my_mysqli_connect($host, $user, $passwd, $db, $port, $socket)) | ||
die("skip Cannot connect to MySQL"); | ||
|
||
include_once("local_infile_tools.inc"); | ||
if ($msg = check_local_infile_allowed_by_server($link)) | ||
die(sprintf("skip %s, [%d] %s", $msg, $link->errno, $link->error)); | ||
|
||
mysqli_close($link); | ||
|
||
?> | ||
--INI-- | ||
open_basedir={PWD} | ||
mysqli.allow_local_infile=1 | ||
mysqli.local_infile_directory={PWD}/foo/bar | ||
--FILE-- | ||
<?php | ||
require_once("connect.inc"); | ||
|
||
if (!$link = my_mysqli_connect($host, $user, $passwd, $db, $port, $socket)) { | ||
printf("[001] Connect failed, [%d] %s\n", mysqli_connect_errno(), mysqli_connect_error()); | ||
} | ||
|
||
if (!$link->query("DROP TABLE IF EXISTS test")) { | ||
printf("[002] [%d] %s\n", $link->errno, $link->error); | ||
} | ||
|
||
if (!$link->query("CREATE TABLE test (id INT UNSIGNED NOT NULL PRIMARY KEY) ENGINE=" . $engine)) { | ||
printf("[003] [%d] %s\n", $link->errno, $link->error); | ||
} | ||
|
||
$filepath = str_replace('\\', '/', __DIR__.'/foo/foo.data'); | ||
if (!$link->query("LOAD DATA LOCAL INFILE '".$filepath."' INTO TABLE test")) { | ||
printf("[004] [%d] %s\n", $link->errno, $link->error); | ||
} | ||
|
||
if ($res = mysqli_query($link, 'SELECT COUNT(id) AS num FROM test')) { | ||
$row = mysqli_fetch_assoc($res); | ||
mysqli_free_result($res); | ||
|
||
$row_count = $row['num']; | ||
$expected_row_count = 3; | ||
if ($row_count != $expected_row_count) { | ||
printf("[005] %d != %d\n", $row_count, $expected_row_count); | ||
} | ||
} else { | ||
printf("[006] [%d] %s\n", $link->errno, $link->error); | ||
} | ||
|
||
$link->close(); | ||
echo "done"; | ||
?> | ||
--CLEAN-- | ||
<?php | ||
require_once('connect.inc'); | ||
|
||
if (!$link = my_mysqli_connect($host, $user, $passwd, $db, $port, $socket)) { | ||
printf("[clean] Cannot connect to the server using host=%s, user=%s, passwd=***, dbname=%s, port=%s, socket=%s\n", | ||
$host, $user, $db, $port, $socket); | ||
} | ||
|
||
if (!$link->query($link, 'DROP TABLE IF EXISTS test')) { | ||
printf("[clean] Failed to drop old test table: [%d] %s\n", mysqli_errno($link), mysqli_error($link)); | ||
} | ||
|
||
$link->close(); | ||
?> | ||
--EXPECT-- | ||
done |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
80 changes: 80 additions & 0 deletions
80
ext/mysqli/tests/mysqli_local_infile_directory_access_allowed.phpt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,80 @@ | ||
--TEST-- | ||
mysqli.local_infile_directory vs access allowed | ||
--SKIPIF-- | ||
<?php | ||
require_once('skipif.inc'); | ||
require_once('skipifconnectfailure.inc'); | ||
|
||
if (!$link = my_mysqli_connect($host, $user, $passwd, $db, $port, $socket)) | ||
die("skip Cannot connect to MySQL"); | ||
|
||
include_once("local_infile_tools.inc"); | ||
if ($msg = check_local_infile_allowed_by_server($link)) | ||
die(sprintf("skip %s, [%d] %s", $msg, $link->errno, $link->error)); | ||
|
||
mysqli_close($link); | ||
|
||
?> | ||
--INI-- | ||
open_basedir={PWD} | ||
mysqli.allow_local_infile=0 | ||
mysqli.local_infile_directory={PWD}/foo | ||
--FILE-- | ||
<?php | ||
require_once("connect.inc"); | ||
|
||
if (!$link = my_mysqli_connect($host, $user, $passwd, $db, $port, $socket)) { | ||
printf("[001] Connect failed, [%d] %s\n", mysqli_connect_errno(), mysqli_connect_error()); | ||
} | ||
|
||
if (!$link->query("DROP TABLE IF EXISTS test")) { | ||
printf("[002] [%d] %s\n", $link->errno, $link->error); | ||
} | ||
|
||
if (!$link->query("CREATE TABLE test (id INT UNSIGNED NOT NULL PRIMARY KEY) ENGINE=" . $engine)) { | ||
printf("[003] [%d] %s\n", $link->errno, $link->error); | ||
} | ||
|
||
$filepath = str_replace('\\', '/', __DIR__.'/foo/foo.data'); | ||
if (!$link->query("LOAD DATA LOCAL INFILE '".$filepath."' INTO TABLE test")) { | ||
printf("[004] [%d] %s\n", $link->errno, $link->error); | ||
} | ||
|
||
$filepath = str_replace('\\', '/', __DIR__.'/foo/bar/bar.data'); | ||
if (!$link->query("LOAD DATA LOCAL INFILE '".$filepath."' INTO TABLE test")) { | ||
printf("[005] [%d] %s\n", $link->errno, $link->error); | ||
} | ||
|
||
if ($res = mysqli_query($link, 'SELECT COUNT(id) AS num FROM test')) { | ||
$row = mysqli_fetch_assoc($res); | ||
mysqli_free_result($res); | ||
|
||
$row_count = $row['num']; | ||
$expected_row_count = 6; | ||
if ($row_count != $expected_row_count) { | ||
printf("[006] %d != %d\n", $row_count, $expected_row_count); | ||
} | ||
} else { | ||
printf("[007] [%d] %s\n", $link->errno, $link->error); | ||
} | ||
|
||
$link->close(); | ||
echo "done"; | ||
?> | ||
--CLEAN-- | ||
<?php | ||
require_once('connect.inc'); | ||
|
||
if (!$link = my_mysqli_connect($host, $user, $passwd, $db, $port, $socket)) { | ||
printf("[clean] Cannot connect to the server using host=%s, user=%s, passwd=***, dbname=%s, port=%s, socket=%s\n", | ||
$host, $user, $db, $port, $socket); | ||
} | ||
|
||
if (!$link->query($link, 'DROP TABLE IF EXISTS test')) { | ||
printf("[clean] Failed to drop old test table: [%d] %s\n", mysqli_errno($link), mysqli_error($link)); | ||
} | ||
|
||
$link->close(); | ||
?> | ||
--EXPECT-- | ||
done |
Oops, something went wrong.