php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #6376 File in include_path is run instead of file in DocumentRoot
Submitted: 2000-08-27 09:14 UTC Modified: 2000-08-27 19:42 UTC
From: rwidmer at developersdesk dot com Assigned:
Status: Closed Package: Scripting Engine problem
PHP Version: 4.0 Latest CVS (27/08/2000) OS: Linux SuSe 6.3
Private report: No CVE-ID: None
 [2000-08-27 09:14 UTC] rwidmer at developersdesk dot com
This was actually found with   www.php.net/~andi/php-4.0.2RC1.tar.gz
compiled as a static apache module.


With RC1 the include_path can override the program being executed.  As
late as 200007300345 it did not.  Also, when PHP encounters a directory
in the path with the same name as the currently executing program it
fails with:

Fatal error: input in flex scanner failed in
/web/hosts/www.southernidahojobs.com/phplib/pre/test.php on line 1


It took a while to figure out that PHP is taking the name of the program
being executed (the URL from the browser) and searching the 
include_path for it. I believe that it should always execute the program 
in DocumentRoot like it has before.
 
Although I first saw the problem with a conflicting directory, I have 
found it is also triggered by conflicting file names.  To see it you 
need a file or directory in the include path, before ./ with the same 
name as the script you are executing.


For example:

in some config file

php_value include_path /path/to/includes:./:/more/paths



in DocumentRoot

test.php:
-------------------------
<?
phpinfo();
?>
-------------------------



in /path/to/includes/

test.php:
-------------------------
hello from the path!
-------------------------



Now hit http://www.somedomain.com/test.php   and you get:

hello from the path! 


At least I do.  If you move test.php from /path/to/includes to
/more/paths it will work properly.  (After the ./ in the include_path)


This is on the new (6.3) SuSe machine using apache 1.3.12, mod-ssl
2.6.5, openssl 0.9.5a and RC1 or the 07/30 shapshot all freshly
compiled from tarballs.  (I started by rm'ing the source directories, 
of apache, mod_ssl and php4 so it should have been a clean compile.)

I get the same error on port 80 and port 443.


Also, if you go to the /path/to/includes directory and:

rm test.php
mkdir test.php


Now you should get:

Fatal error: input in flex scanner failed in
/web/hosts/www.southernidahojobs.com/phplib/pre/test.php on line 1


This is probably not too unreasonable, but I had to take a break after a
couple hours trying to track it down before I could figure out that it
was a matter of pointing php at a directory rather than a file.

Without the include_path bug I don't think you could possibly get here
if you hit a directory with apache it handles it before deciding to call php.


I hope I am not the only one who can see this one...


./configure options...


php4:

/configure --with-mysql=../mysql \
            --with-apache=../apache \
            --with-config-file-path=/web/conf
            --enable-track-vars



apache:

SSL_BASE=../openssl \
/configure --prefix=/usr/local/apache \
            --enable-module=ssl \
            --enable-module=info \
            --enable-module=rewrite \
            --enable-module=log_referer \
            --disable-module=userdir \
            --activate-module=src/modules/php4/phplib4.a \
            --enable-module=php4   

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-08-27 19:42 UTC] rwidmer at developersdesk dot com
Closed by user.

This was fixed in the 200008271545 shapshot.


 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 10:00:02 2026 UTC