Bug #15801 Updated: unjustified open_basedir restriction on copy()
| From: | vedad at kajtaz dot net | Date: | Fri, 01 Mar 2002 03:14:47 +0000 |
| Subject: | Bug #15801 Updated: unjustified open_basedir restriction on copy() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-1371@lists.php.net to get a copy of this message | ||
ID: 15801
Updated by: vedad@kajtaz.net
Reported By: vedad@kajtaz.net
Status: Open
Bug Type: Filesystem function related
Operating System: linux rh
PHP Version: 4.1.2
New Comment:
okay, i get the point...
but what about include() and upload_tmp_dir ?
if there were using the same mechanism as copy() (sorry i never had
much to look inside php source and verify by myself), they'd raise an
error too, right?
(they still point to symlinked path, and they still work, unlike copy()
)
Previous Comments:
------------------------------------------------------------------------
[2002-02-28 22:10:45] vedad@kajtaz.net
Okay, i finally got it to work...
copy() doesnt seem to like symbolic links... when *both* open_basedir
and copy(path1, path2) paths are set to the "real" path, copy works...
However, that's still weird, as referencing files with symlinked path
by other means (auto_prepend_file and upload_tmp_dir config directives
and include() ) works without raising open_basedir error...
and also because this was working prior to 4.0.6, and, imha, it doesnt
make things more secure than before.
------------------------------------------------------------------------
[2002-02-28 22:07:28] rasmus@php.net
Well, the reason it works in 4.0.4 is that no open_basedir check is
done at all on copy() in that version. It is wide open. Now the check
is done, and yes, in your case it is due to the symlink you have. The
open_basedir check is currently not very good at dealing with symlinked
directories.
------------------------------------------------------------------------
[2002-02-28 21:32:31] vedad@kajtaz.net
Hi again,
i've got the same problem with 4.1.0 with mime upload patch...
While uploaded-file-copy may be circumvented with move_uploaded_file, i
found no solution for copying not-uploaded files from one place to
another. Note i'm always using full path in copy() and
move_uploaded_file(), and that all paths are within open_basedir
folder...
I've got no choice but downgrading even more... :(
------------------------------------------------------------------------
[2002-02-28 20:48:41] vedad@kajtaz.net
I've done some tests, and this is not specific to uploaded file. The
copy() doesn't work at all any more, always giving open_basedir error.
I've checked phpinfo() output from faulty scripts, and open_basedir
paths are correct.
Please let me know if you need more info...
-- vedad
------------------------------------------------------------------------
[2002-02-28 20:07:05] vedad@kajtaz.net
Hello,
I've got a weird open_basedir restriction error on copy() of an
uploaded file. This occurs with php4.1.2, after upgrading from the old
4.0.4pl1, which didn't have the problem. php.ini and apache
configuration were unchanged.
Virtual host settings:
php_admin_value open_basedir /path/to/website/
php_admin_value upload_tmp_dir /path/to/website/temp
I'm now getting an error when file is being copied from
/path/to/website/temp/<phptempfile> to /path/to/website/somewhereelse/
Error label:
Warning: open_basedir restriction in effect. File is in wrong directory
in /path/to/website/somescript.phtml on line 1055
As copy-source, copy-destination and tmp folder are all within
open_basedir, I really don't get the problem.
Am I missing something?
Please note that in my case, /path/to/website is a symbolic link to
/mnt/mountpoint/to/website, but i had no more success by putting the
"real" path into open_basedir section.
Thanx,
-- vedad
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=15801&edit=1