php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #23282 include and require break with "./"
Submitted: 2003-04-19 21:48 UTC Modified: 2003-04-29 05:19 UTC
From: russell+php dot net at loosenut dot com Assigned:
Status: Closed Package: Scripting Engine problem
PHP Version: 4.3.2RC1 OS: Solaris
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: russell+php dot net at loosenut dot com
New email:
PHP Version: OS:

 

 [2003-04-19 21:48 UTC] russell+php dot net at loosenut dot com
It would appear that "include" and "require" bork if you include a file with "./" -- however, excluding the dot-slash, the files are correctly included from the current directory or relative subdirectories.  Previous versions of PHP (testing in 4.1.s) work just fine with identical scripts.

According to "phpinfo();" run on the server in this same directory, I have:

Directive: include_path
Local Value: .:/usr/local/php-4.3.2rc1/lib/php
Master Value: .:/usr/local/php-4.3.2rc1/lib/php 

Safe mode is also off.

Test case:

-- begin
<HTML>
<HEAD>
  <TITLE>PHP Test Case</TITLE>
</HEAD>

<BODY>

<P>
Testing:

<?PHP
// index.php

print( "Including file:<BR>\n" );
include( "file.php" );

print( "Including file with dot-slash:<BR>\n" );
include( "./file.php" );

?>

</BODY>
</HTML>
-- end

-- begin
<?PHP
// file.php

print( "<B>File Successfully Included</B><BR>\n" );

?>
-- end

...if all goes well, you should see "File Successfully Included" twice -- however, it only shows up once and the second line shows an error in the error logs.

Here are the error messages that the two above files generate (Apache 1.3.27):

-- begin
[Thu Apr 17 02:38:11 2003] [error] PHP Warning:  main (./file.php) [<a
href='http://www.php.net/function.main'>function.main</a>]: failed to open stream: No such file or directory in
/export/home/russell/public_html/inc-problem/index.php on line 18
[Thu Apr 17 02:38:11 2003] [error] PHP Warning:  main() [<a
href='http://www.php.net/function.include'>function.include</a>]: Failed opening './file.php' for inclusion
(include_path='.:/usr/local/php-4.3.2rc1/lib/php') in
/export/home/russell/public_html/inc-problem/index.php on line 18
-- end



Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2003-04-21 09:55 UTC] sniper@php.net
This is how it's supposed to work.

 [2003-04-21 13:20 UTC] russell+php dot net at loosenut dot com
Well, this effectively breaks relative directory includes, then... you can no longer write complex scripts that "know" their own directory structure, doing something like:

include( "../include/db.inc" );

..or similiar, since the "." b0rks the inclusion.  IMO this is bad behaviour (and contrary to the way relative file pathing works in either the UN*X shell or the simply the web itself).
 [2003-04-21 21:49 UTC] philip@php.net
Woah, is this report really saying that include './foo.php' will no longer work?!  Why?  This would be a huge BC issue.
 [2003-04-22 00:59 UTC] rasmus@php.net
This works just fine in PHP 4.3.  The output from your test script here is:

Including file:
File Successfully Included
Including file with dot-slash:
File Successfully Included

There must be something else going on you aren't telling us about.
 [2003-04-22 03:10 UTC] russell+php dot net at loosenut dot com
Well, the "this is how it's supposed to work" was a tad unclear.  Is there something else I can provide that could help you figure out what was happening?  This is basically a "straight out of the box configuration" and, as I said, swapping back to an older version of PHP "works just fine."

On this server, I'm using the packaged "php.ini-recommended" file, only slightly modified:

-- begin
% diff -c php.ini php.ini-recommended
*** php.ini     Mon Apr  7 03:30:42 2003
--- php.ini-recommended Sun Mar  2 17:31:48 2003
***************
*** 229,236 ****
  ; (e.g. by adding its signature to the Web server header).  It is no security
  ; threat in any way, but it makes it possible to determine whether you use PHP
  ; on your server or not.
! ;expose_php = On
! expose_php = Off
  
  
  ;;;;;;;;;;;;;;;;;;;
--- 229,235 ----
  ; (e.g. by adding its signature to the Web server header).  It is no security
  ; threat in any way, but it makes it possible to determine whether you use PHP
  ; on your server or not.
! expose_php = On
  
  
  ;;;;;;;;;;;;;;;;;;;
-- end
 [2003-04-22 03:15 UTC] rasmus@php.net
RC1 is rather old and there may have been a bug in that.  No idea.  Try current 4.3 CVS from http://snaps.php.net
 [2003-04-29 05:19 UTC] russell+php dot net at loosenut dot com
Just a confirmation that I've tried and verified that this is fixed in 4.3.2RC2 released for beta earlier today -- identical config files and compilation options.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 17:00:01 2026 UTC