From 0a0e8159a88785388452616f921f83a9ede593fd Mon Sep 17 00:00:00 2001 From: Tonya Mork Date: Fri, 15 Oct 2021 22:57:47 +0000 Subject: [PATCH] FileSystem API: Add safeguard for invalid return from `get_attached_file()` in `wp_delete_attachment()`. The `get_attached_file()` function is supposed to return the path to the file, but could: 1. Return `false` if the file doesn't exist. 2. Return literally anything else, as a filter is being applied to the value on return. As the `clean_dirsize_cache()` now has input validation, passing anything but a non-empty string to `clean_dirsize_cache()` will result in a PHP error notice. This was exposed by the `Tests_Post_GetPostStatus::wpSetUpBeforeClass()` method which started generating unexpected output (the doing it wrong message) during the test run. While this indicates that there is a flaw in the mocking being done in the test suite, debugging that is outside of the scope of the current patch. At the same time, as based on the above point, this ''could'' potentially happen in a real-world situation as well, adding additional conditions to the `if` in the `wp_delete_attachment()` function before calling the `clean_dirsize_cache()` function, is warranted. As there are no tests for the `wp_delete_attachment()` function at all at this time, we're not adding a test specifically for this change for now. This should however be addressed in the future, when tests will be added to cover the `wp_delete_attachment()` function completely. Follow-up to [32619], [49212], [51910]. Props jrf, hellofromTonya. See #52241. git-svn-id: https://develop.svn.wordpress.org/trunk@51912 602fd350-edb4-49c9-b593-d223f7449a82 --- src/wp-includes/post.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/wp-includes/post.php b/src/wp-includes/post.php index b13942002a..7073328c0d 100644 --- a/src/wp-includes/post.php +++ b/src/wp-includes/post.php @@ -6162,7 +6162,7 @@ function wp_delete_attachment( $post_id, $force_delete = false ) { $backup_sizes = get_post_meta( $post->ID, '_wp_attachment_backup_sizes', true ); $file = get_attached_file( $post_id ); - if ( is_multisite() ) { + if ( is_multisite() && is_string( $file ) && ! empty( $file ) ) { clean_dirsize_cache( $file ); }