Bug #55804 [Com]: tempnam(): wrong fallback to /tmp
| From: | jo at feuersee dot de | Date: | Mon, 19 Jan 2015 16:48:16 +0000 |
| Subject: | Bug #55804 [Com]: tempnam(): wrong fallback to /tmp | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190058@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55804&edit=1
ID: 55804
Comment by: jo at feuersee dot de
Reported by: spam2 at rhsoft dot net
Summary: tempnam(): wrong fallback to /tmp
Status: Open
Type: Bug
Package: Safe Mode/open_basedir
Operating System: Linux
PHP Version: 5.3.8
Block user comment: N
Private report: N
New Comment:
May I propose to clarify the documentation then, pls? It currently reads: "If the directory
does not exist, tempnam() may generate a file in the system's temporary directory, and return
the full path to that file, including its name."
In fact it should hint the permission relation:
"If the directory does not exist or is not writeable ..."
And the fallback behavios should vanish in PHP7
Previous Comments:
------------------------------------------------------------------------
[2011-09-28 09:42:28] spam2 at rhsoft dot net
your definition of "easy solution" is a little bit strange
how can it be easy to set a ENV-Var for 500 domains where
only most of them use docroot/temp/
a smarter fallback would be the configured uploadtemp but not /tmp
------------------------------------------------------------------------
[2011-09-28 09:28:44] pajoye@php.net
I was wrong about the removal, that's only for tmpfile.
The rest of my comment remains (BC break and easy solution).
------------------------------------------------------------------------
[2011-09-28 09:22:29] spam2 at rhsoft dot net
they are not removed or how should a stat-call in a terminal show that they are existing? anyways -
they must not be created
Warning: fopen() [function.fopen.php]: open_basedir restriction in effect. File(/tmp/rhcsv5f9RIs) is
not within the
allowed path(s):
(/mnt/data/www/beta.rhsoft.net:/Volumes/dune/www-servers/phpincludes:/var/www/uploadtemp) in
/mnt/data/www/beta.rhsoft.net/tempname.php on line 6
Warning: fopen(/tmp/rhcsv5f9RIs) [function.fopen.php]: failed to open stream: Operation not
permitted in
/mnt/data/www/beta.rhsoft.net/tempname.php on line 6
[harry@srv-rhsoft:~]$ stat /tmp/rhcsv5f9RIs
Datei: â/tmp/rhcsv5f9RIsâ
GröÃe: 0 Blöcke: 0 EA Block: 4096 reguläre leere Datei
Gerät: 809h/2057d Inode: 48 Verknüpfungen: 1
Zugriff: (0600/-rw-------) Uid: ( 48/ apache) Gid: ( 48/ apache)
Zugriff : 2011-09-28 08:58:01.046916064 +0200
Modifiziert: 2011-09-28 08:58:01.046916064 +0200
Geändert : 2011-09-28 08:58:01.046916064 +0200
------------------------------------------------------------------------
[2011-09-28 09:14:51] pajoye@php.net
if the files are not removed on request or sapi shutdown, then we have a bug.
------------------------------------------------------------------------
[2011-09-28 09:13:01] spam2 at rhsoft dot net
> Documented behavior, changing it will break BC
what sort of BC?
the created file is outside open_basedir, can not be used and can not be deleted
so this file is useless and simply at the wrong location
i can not imagine any code which useful relies on that "feature"
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=55804
--
Edit this bug report at https://bugs.php.net/bug.php?id=55804&edit=1