Skip to content

Fix GH-21992: symlink() creates link at dangling symlink target - #24248

Open
bukka wants to merge 1 commit into
php:PHP-8.4from
bukka:file_symlink_dangling_link
Open

bukka wants to merge 1 commit into
php:PHP-8.4from
bukka:file_symlink_dangling_link

Conversation

@bukka

@bukka bukka commented Oct 10, 2026

Copy link
Copy Markdown
Member

Fixes #21992.

expand_filepath() resolves the last component of the link path, so when it is an existing dangling symlink, the new link is silently created at the symlink target and symlink() returns true. link() has the same problem.

This resolves only the directory part of the link path and keeps the last component as given, so the kernel reports EEXIST for any existing entry (including a dangling symlink) and the usual "File exists" warning is emitted. No extra pre-check is needed, so there is no race between the check and the link creation.

Supersedes #22024, which added an lstat/stat pre-check instead of fixing the path resolution and did not cover link().

expand_filepath() resolves the last component of the link path, so when
it is an existing dangling symlink, the new link is created at its target
instead of failing. The same applies to link(). Resolve only the directory
part and keep the last component as given so the kernel reports EEXIST.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant