Bug #53597 [Tbd]: open_basedir not working as documented

From: Date: Mon, 10 Jan 2011 15:31:14 +0000
Subject: Bug #53597 [Tbd]: open_basedir not working as documented
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-157797@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=53597&edit=1

 ID:                 53597
 Updated by:         pajoye@php.net
 Reported by:        hsk at fli-leibniz dot de
 Summary:            open_basedir not working as documented
 Status:             To be documented
 Type:               Bug
 Package:            Safe Mode/open_basedir
 Operating System:   Linux
 PHP Version:        5.3.4
 Assigned To:        pajoye
 Block user comment: N
 Private report:     N

 New Comment:

Docs need to be updated but that won't change.


Previous Comments:
------------------------------------------------------------------------
[2011-01-10 16:31:11] pajoye@php.net

Docs need to be updated but that won't change.

------------------------------------------------------------------------
[2011-01-10 15:34:55] aharvey@php.net

Ah, I see what you're getting at now. My apologies for closing the bug.

------------------------------------------------------------------------
[2011-01-10 14:38:23] hsk at fli-leibniz dot de

#53597 is definitely *not* a duplicate of #53577, please change status

open_basedir as of 5.3.4 (and 5.3.5 as well) no longer allows to specify
directory prefixes, in contradiction to the documentation

e.g., setting
  open_basedir = /u/phpMyAdmin
should accept files in /u/phpMyAdmin-3.3.8.1-all-languages, but does not

------------------------------------------------------------------------
[2010-12-24 05:29:41] aharvey@php.net

Duplicate of bug #53577.

------------------------------------------------------------------------
[2010-12-23 12:38:27] hsk at fli-leibniz dot de

Description:
------------
the php manual in the section "Description of core php.ini directives"
(http://www.php.net/manual/en/ini.core.php, checked on 23-dec-10 11:55
utc)
states:

The restriction specified with open_basedir is actually a prefix, not a
directory name.

this has been so "ever since", but seems now broken at release 5.3.4 -
specifying directory name prefix gives access denied errors, only
specifying complete directory name seems to work.

if the described behaviour is intentional, please fix the documentation
*and note the change in BIG BOLD LETTERS in the release announcement*,
or, better, fix the php-code to behave as documented.

Test script:
---------------
phpmyadmin installed and configured in
/u/phpMyAdmin-3.3.8.1-all-languages

entry in /usr/lib/php.ini :

open_basedir = /tmp/:/u/phpMyAdmin:/usr/lib/php/

according to the documentation, this should give access to the
phpmyadmin installation, and used to do so up to php-5.3.3, but now, as
of php-5.3.4, gives an error message
open_basedir restriction in effect.
File(/u/phpMyAdmin-3.3.8.1-all-languages/index.php) is not within the
allowed path(s): (/tmp/:/u/phpMyAdmin:/usr/lib/php/)

it works when changing /usr/lib/php.ini to 
open_basedir = /tmp/:/u/phpMyAdmin-3.3.8.1-all-languages:/usr/lib/php/



------------------------------------------------------------------------



-- 
Edit this bug report at http://bugs.php.net/bug.php?id=53597&edit=1


Thread (9 messages)

« previous php.bugs (#157797) next »