Bug #17927 Updated: open_basedir is not working
| From: | matt at haught dot com | Date: | Mon, 24 Jun 2002 18:35:12 +0000 |
| Subject: | Bug #17927 Updated: open_basedir is not working | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-11958@lists.php.net to get a copy of this message | ||
ID: 17927
Updated by: matt@haught.com
Reported By: matt@haught.com
-Status: Feedback
+Status: Open
Bug Type: Apache2 related
Operating System: FreeeBSD 4.4-RELEASE
PHP Version: php4-200206222100 snap
New Comment:
I just tested this on FreeBSD 4.6-RELEASE and the problem
is also occuring there. To test this i created a file in
my /usr/local/www/data directory that has:
<?php
include (../matt.php);
phpinfo();
?>
amd in /usr/local/www i created the file matt.php with
just a echo of my name and some <br>'s.
I then set the open_basedir in php.ini to
/usr/local/www/data and tested it, and then just via
php_admin_value, and then both. And in all cases i was
allowed to include matt.php which is not in the set
open_basedir. I also tried including /etc/passwd and was
again successful. Could someone please try to do the
same? I am using the latest snap as of this post.
Previous Comments:
------------------------------------------------------------------------
[2002-06-23 14:15:52] matt@haught.com
Ok to make matters even more odd, one of my pages calls opendir(), and
get open_basedir error "open_basedir restriction in effect. File is in
wrong directory ", it seems to be working for opendir(), but not when
opening the first page or its includes. I know it is probably a problem
with apache2+freebsd. Is their anyone else having the same problem, or
does anyone have any tests they want me to run? I know apache2 is low
on the priority list, so don't sweat it.
--Matt
------------------------------------------------------------------------
[2002-06-23 10:11:09] matt@haught.com
I just updated to php4-200206230600, and it is still a no go. I have
done a little more testing, I removed all the php_admin_* and php_*
directives from httpd.conf, and I set the php.ini setting for
open_basedir to /tmp (the pages are not there) so that it is the only
place it is set. It shows up in phpinfo() as /tmp in both local and
master, but it still does not work as I receive no errors when opening
a page or including a page from elsewhere. It seems that the settings
for open_basedir are being set, but just not acted on.
------------------------------------------------------------------------
[2002-06-23 05:21:19] derick@php.net
As this was change very recently... you might got a snapshot which
didn't have the fix in it... can you please try a later one?
Derick
------------------------------------------------------------------------
[2002-06-23 01:25:10] matt@haught.com
I tried php4-200206222100 snap, got the same result.
------------------------------------------------------------------------
[2002-06-22 19:40:52] matt@haught.com
I am using the php_admin_value to set the open_basedir option within a
<VirtualHost>, the option is accepted by apache-2.0.39 and is reflected
by phpinfo(). I just moved my sites around and I forgot to change my
open_basedir, and to my amazement i got no errors when opening any of
the pages. I also have open_basedir set to /usr/local/www/data as a
default in my php.ini (mostly to remind me to set it for the virtual
host's dir which is not in that dir). I can change the values to
anything in either the ini or through php_admin_value and no
restrictions are put into place. I put this bug into apache2 releated,
but I am not sure if it is reflected in others. I am using
php4-200206211500 snap.
As a side note, php_admin_flag engine Off, also does nothing inside a
<VirtualHost> or a <Location>, I am not sure if it is related.
php_value include_path /dir, DOES work properly.
--Matt
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17927&edit=1