Bug #17927 Updated: open_basedir is not working

From: Date: Mon, 24 Jun 2002 18:35:12 +0000
Subject: Bug #17927 Updated: open_basedir is not working
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-11958@lists.php.net to get a copy of this message
ID: 17927 Updated by: matt@haught.com Reported By: matt@haught.com -Status: Feedback +Status: Open Bug Type: Apache2 related Operating System: FreeeBSD 4.4-RELEASE PHP Version: php4-200206222100 snap New Comment: I just tested this on FreeBSD 4.6-RELEASE and the problem is also occuring there. To test this i created a file in my /usr/local/www/data directory that has: <?php include (../matt.php); phpinfo(); ?> amd in /usr/local/www i created the file matt.php with just a echo of my name and some <br>'s. I then set the open_basedir in php.ini to /usr/local/www/data and tested it, and then just via php_admin_value, and then both. And in all cases i was allowed to include matt.php which is not in the set open_basedir. I also tried including /etc/passwd and was again successful. Could someone please try to do the same? I am using the latest snap as of this post. Previous Comments: ------------------------------------------------------------------------ [2002-06-23 14:15:52] matt@haught.com Ok to make matters even more odd, one of my pages calls opendir(), and get open_basedir error "open_basedir restriction in effect. File is in wrong directory ", it seems to be working for opendir(), but not when opening the first page or its includes. I know it is probably a problem with apache2+freebsd. Is their anyone else having the same problem, or does anyone have any tests they want me to run? I know apache2 is low on the priority list, so don't sweat it. --Matt ------------------------------------------------------------------------ [2002-06-23 10:11:09] matt@haught.com I just updated to php4-200206230600, and it is still a no go. I have done a little more testing, I removed all the php_admin_* and php_* directives from httpd.conf, and I set the php.ini setting for open_basedir to /tmp (the pages are not there) so that it is the only place it is set. It shows up in phpinfo() as /tmp in both local and master, but it still does not work as I receive no errors when opening a page or including a page from elsewhere. It seems that the settings for open_basedir are being set, but just not acted on. ------------------------------------------------------------------------ [2002-06-23 05:21:19] derick@php.net As this was change very recently... you might got a snapshot which didn't have the fix in it... can you please try a later one? Derick ------------------------------------------------------------------------ [2002-06-23 01:25:10] matt@haught.com I tried php4-200206222100 snap, got the same result. ------------------------------------------------------------------------ [2002-06-22 19:40:52] matt@haught.com I am using the php_admin_value to set the open_basedir option within a <VirtualHost>, the option is accepted by apache-2.0.39 and is reflected by phpinfo(). I just moved my sites around and I forgot to change my open_basedir, and to my amazement i got no errors when opening any of the pages. I also have open_basedir set to /usr/local/www/data as a default in my php.ini (mostly to remind me to set it for the virtual host's dir which is not in that dir). I can change the values to anything in either the ini or through php_admin_value and no restrictions are put into place. I put this bug into apache2 releated, but I am not sure if it is reflected in others. I am using php4-200206211500 snap. As a side note, php_admin_flag engine Off, also does nothing inside a <VirtualHost> or a <Location>, I am not sure if it is related. php_value include_path /dir, DOES work properly. --Matt ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17927&edit=1

« previous php.bugs (#11958) next »