Req #63533 [Asn->Wfx]: new php.ini flag disable_execute
| From: | bjori@php.net | Date: | Mon, 10 Feb 2014 04:36:51 +0000 |
| Subject: | Req #63533 [Asn->Wfx]: new php.ini flag disable_execute | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184230@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=63533&edit=1
ID: 63533
Updated by: bjori@php.net
Reported by: thbley at gmail dot com
Summary: new php.ini flag disable_execute
-Status: Assigned
+Status: Wont fix
Type: Feature/Change Request
Package: *Configuration Issues
Operating System: all
PHP Version: 5.5.0alpha1
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
These functions aren't marked specifically and don't need any special attributes - meaning
we can't magicly decide that those functions execute anything.
That in turn means any new extension, or even existing pecl extension, would not be protected by
that feature - making it useless.
We found this out the hard way.. This sort of thing don't work.
Besides - we don't want to add more ini options.
Previous Comments:
------------------------------------------------------------------------
[2012-11-15 21:29:35] thbley at gmail dot com
Description:
------------
add new flag to php.ini:
disable_execute = On|Off
(default: On?)
which is the same as:
disable_functions = exec,shell_exec,passthru,system,popen,proc_open,pcntl_exec
=> make secure configuration easier
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=63533&edit=1