about summary refs log tree commit diff
path: root/sourcecodes/add_evd.php
diff options
context:
space:
mode:
authorClaude Sonnet 52026-08-17 19:26:43 +0000
committerFrederick Muriuki Muriithi2026-08-17 14:53:08 -0500
commit9cae7ea19c7c744a1ed2bd997571ec1b516a0d32 (patch)
treece73195519a319bb0dc72d75df4d77a8ac584141 /sourcecodes/add_evd.php
parent4825da8e49c302392fe6018862dfcdd6f91c6192 (diff)
downloadBNW-9cae7ea19c7c744a1ed2bd997571ec1b516a0d32.tar.gz
Guard fopen() results with a false-check before fwrite/fprintf/fclose
On PHP 7.4, calling fwrite()/fprintf()/fclose() with a false handle
(a failed fopen(), e.g. from a bad path, missing directory, or
permissions issue) just emits a warning and no-ops. On PHP 8.0+, these
functions require a resource argument and throw an uncaught TypeError
instead, turning what used to be a silent degradation into a fatal
crash of the whole request.

This patch wraps every fopen()-then-write call site in the codebase
(18 files) with an `if ($handle !== false) { ... }` check, matching
the existing pattern used elsewhere in the codebase. Where the same
$fpvar handle is threaded through shared helper functions
(enter_ban_list/banlist/whitelist, duplicated across
remove_variables_processing.php, remove_variables_processing_default.php,
modify_structure_learning.php and tier_description_processing_gom.php),
the guard was added inside those functions too for consistency, even
though the call sites are currently dead/commented-out in three of the
four files — so the same landmine doesn't reappear if that code is
ever re-enabled.

Verified empirically against PHP 8.3.28: fopen() on an unwritable path
followed by fwrite() on the resulting `false` throws
  TypeError: fwrite(): Argument #1 ($stream) must be of type resource, false given
without the guard; with the guard, the call is skipped instead of
crashing. The normal (successful fopen) path was also re-run through
mat_structure.php's structure_change() and still produces identical
output to before the change.

Reviewed by: Frederick M Muriithi <fredmanglis@gmail.com>
Diffstat (limited to 'sourcecodes/add_evd.php')
-rw-r--r--sourcecodes/add_evd.php30
1 files changed, 16 insertions, 14 deletions
diff --git a/sourcecodes/add_evd.php b/sourcecodes/add_evd.php
index 008844b8..21406efd 100644
--- a/sourcecodes/add_evd.php
+++ b/sourcecodes/add_evd.php
@@ -115,16 +115,17 @@ if($dt!=1)
 
 
 
- $ft=$dir."$keyval"."var.txt"; 
- $f1=fopen("$ft","w");  
+ $ft=$dir."$keyval"."var.txt";
+ $f1=fopen("$ft","w");
  $ft=$dir."$keyval"."vardata.txt";
- $f2=fopen("$ft","w");  
+ $f2=fopen("$ft","w");
  $ft=$dir."$keyval"."varname.txt";
  $f3=fopen("$ft","w");
 
 
 $pos = strpos($fpvarname, $sym);
 
+if ($f1 !== false && $f2 !== false && $f3 !== false) {
 if($fpvarname=="")
 {
   fwrite($f1,$vriable);
@@ -132,11 +133,11 @@ if($fpvarname=="")
   fwrite($f3,$sym);
 
 }
-else 
+else
 {
-  if ($pos === false)// append at buttom as new records 
+  if ($pos === false)// append at buttom as new records
   {
-  
+
      $fpvar=$fpvar."\t".$vriable;
      fwrite($f1,$fpvar);
 
@@ -147,7 +148,7 @@ else
      fwrite($f3,$fpvarname);
 
   }
-  else 
+  else
   {
      $cld=explode("\t",$fpvarname);
      $j=0;
@@ -158,12 +159,12 @@ else
         if($cc==$sym)
         {
               $inx=$j;
-        } 
+        }
         $j++;
-    
+
      }
 
- 
+
      fwrite($f1,$fpvar);
      fwrite($f3,$fpvarname);
 
@@ -178,18 +179,19 @@ else
               $inx=$j;
               fprintf($f2,"%s\t",$textdata);
         }
-        else 
-        {          
+        else
+        {
               fprintf($f2,"%s\t",$cc);
         }
-        
+
         $j++;
-    
+
      }
 
    }
 
 }
+}
 
 
   //execute shell script for matlab