Req #68125 [NEW]: [FPM] check if script is in specified path before execute (ie docroot)

From: Date: Wed, 01 Oct 2014 18:20:15 +0000
Subject: Req #68125 [NEW]: [FPM] check if script is in specified path before execute (ie docroot)
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187782@lists.php.net to get a copy of this message
From: stefan at eriksson dot cn Operating system: Linux PHP version: Irrelevant Package: FPM related Bug Type: Feature/Change Request Bug description:[FPM] check if script is in specified path before execute (ie docroot) Description: ------------ I'm looking for a kind of middle ground between chrooted fpm environment and non-chrooted env. Suphp offer: ;Path all scripts have to be in docroot=/var/www/ ;Check wheter script is within DOCUMENT_ROOT check_vhost_docroot=true Two different options to specify that a php script has to be in the docroot or else it wont execute. However if the script calls a binary for example with exec() /bin/convert this is doable,so it wont chroot the env just set a restriction on where the php files have to be. This will hinder fpm to run phpfiles added to /tmp etc. From suphp docs: check_vhost_docroot: Checks wheter the script is within DOCUMENT_ROOT specified by the webserver. This option is intended to avoid symbol links outside of the webpage directory. You may want to disable it, when you are using mod_vhost_alias or the Alias-directive. This option is disabled by default, if at compile-time the "--disable-check-docroot" option has been specified, otherwise it is enabled by default. docroot: Patterns matching all allowed script directories. This is an additional security check, especially when check_vhost_docroot is disabled. Defaults to "/*" thus allowing scripts in any location being run. May contain the "*" character which matches zero to n characters excluding the "/" character. Multiple values are allowed for this setting. May contain variables as described above. It would be great if php-fpm could offer the same feature as above, please let me know if there is any more info you need. -- Edit bug report at https://bugs.php.net/bug.php?id=68125&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68125&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68125&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68125&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=68125&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=68125&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=68125&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=68125&r=needscript Try newer version: https://bugs.php.net/fix.php?id=68125&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=68125&r=support Expected behavior: https://bugs.php.net/fix.php?id=68125&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=68125&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=68125&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=68125&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68125&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=68125&r=dst IIS Stability: https://bugs.php.net/fix.php?id=68125&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=68125&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=68125&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=68125&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=68125&r=mysqlcfg

« previous php.bugs (#187782) next »