Skip to content

Regression in fix for GHSA-9f67-6fw4-hpfp: bare device name "NUL" can not be opened if open_basedir is set. #24148

Description

@jbaron-gingco

Description

The following code:

<?php

echo PHP_VERSION . "\n";

function run()
{
	echo 'open_basedir=', var_export(ini_get('open_basedir'), true) . "\n";

	error_clear_last();
	var_dump(@fopen('NUL', 'w'), error_get_last()['message'] ?? null);

	error_clear_last();
	$result = @proc_open('cmd /c ver', [['pipe', 'r'], ['file', 'NUL', 'w'], ['file', 'NUL', 'w']], $pipes);
	var_dump($result, error_get_last()['message'] ?? null);
}

run();

ini_set('open_basedir', '\\;NUL');
run();

ini_set('open_basedir', '\\');
run();

Resulted in this output:

8.5.11
open_basedir=''
resource(5) of type (stream)
NULL
resource(9) of type (process)
NULL
open_basedir='\\;NUL'
resource(10) of type (stream)
NULL
resource(14) of type (process)
NULL
open_basedir='\\'
bool(false)
string(58) "fopen(NUL): Failed to open stream: Operation not permitted"
bool(false)
string(62) "proc_open(NUL): Failed to open stream: Operation not permitted"

But I expected this output instead:

8.5.11
open_basedir=''
resource(5) of type (stream)
NULL
resource(9) of type (process)
NULL
open_basedir='\\;NUL'
resource(10) of type (stream)
NULL
resource(14) of type (process)
NULL
open_basedir='\\'
resource(15) of type (stream)
NULL
resource(19) of type (process)
NULL

Adding 'NUL' to the open_basedir makes it work again.

This happens in PHP 8.3.35, 8.4.26 and 8.5.11. In PHP 8.3.33, 8.4.25 and 8.5.10 the output is as expected. I have not checked PHP 8.6.

This breaks symfony/process because they pass the NUL device to processes on Windows.

PHP Version

PHP 8.5.11 (cli) (built: Sep 22 2026 13:51:38) (NTS Visual C++ 2022 x64)
Copyright (c) The PHP Group
Built by The PHP Group
Zend Engine v4.5.11, Copyright (c) Zend Technologies
    with Zend OPcache v8.5.11, Copyright (c), by Zend Technologies

PHP 8.4.26 (cli) (built: Sep 22 2026 15:11:32) (NTS Visual C++ 2022 x64)
Copyright (c) The PHP Group
Built by The PHP Group
Zend Engine v4.4.26, Copyright (c) Zend Technologies

PHP 8.3.35 (cli) (built: Sep 22 2026 11:14:27) (NTS Visual C++ 2019 x64)
Copyright (c) The PHP Group
Zend Engine v4.3.35, Copyright (c) Zend Technologies

Operating System

Windows Server 2022

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions