fix: disable the phar wrapper globally - #41406
Merged
Merged
Conversation
|
Thanks for opening this pull request! The maintainers of this repository would appreciate it if you would create a changelog item based on your changes. |
This is needed because phpstan seems to require the phar wrapper to work. Phpstan is currently bootstrapping the lib/kernel.php file, so we can't disable the phar wrapper there.
|
11 tasks
DeepDiver1975
approved these changes
Sep 18, 2025
|
|
||
| // disable phar handler in web requests | ||
| if (!self::$CLI) { | ||
| stream_wrapper_unregister("phar"); |
There was a problem hiding this comment.
I now get an error logged by this for every request:
[Mon Dec 08 11:22:57.365104 2025] [proxy_fcgi:error] [pid 86763] [client 192.168.1.10:33223] AH01071: Got error 'PHP message: PHP Warning: stream_wrapper_unregister(): Unable to unregister protocol phar:// in /opt/www/owncloud/lib/kernel.php on line 574'
[Mon Dec 08 11:22:57.365212 2025] [proxy:debug] [pid 86763] proxy_util.c(2832): AH00943: FCGI: has released connection for (*:80)
The log was very noisy, so I modified the code thus:
--- lib/kernel.php 2025-07-03 09:54:27.000000000 -0400
+++ lib/kernel.php 2025-12-08 12:00:22.079292000 -0500
@@ -571,5 +571,5 @@
// disable phar handler in web requests
- if (!self::$CLI) {
+ if (!self::$CLI and in_array('phar', stream_get_wrappers())) {
stream_wrapper_unregister("phar");
}This helped...
I don't like this creation — and checking — a dictionary for every request, but logging an error is even costlier. Maybe, there is a better way of determining, whether the phar-wrapper is registered in the first place...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Description
Phar wrapper won't be allowed by default. If needed, consider to enable it, do your thing, and disable it again; limiting the exposure to what is strictly needed.
Related Issue
Motivation and Context
How Has This Been Tested?
Manually tested, weird things with ".phar" files don't happen.
Screenshots (if appropriate):
Types of changes
Checklist: