Bug #55804 [PATCH]: tempnam(): wrong fallback to /tmp

From: Date: Sat, 18 Apr 2015 00:33:22 +0000
Subject: Bug #55804 [PATCH]: tempnam(): wrong fallback to /tmp
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192176@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=55804&edit=1 ID: 55804 Patch added by: cmb@php.net Reported by: spam2 at rhsoft dot net Summary: tempnam(): wrong fallback to /tmp Status: Open Type: Bug Package: Safe Mode/open_basedir Operating System: Linux PHP Version: 5.3.8 Block user comment: N Private report: N New Comment: The following patch has been added/updated: Patch Name: doc-55804 Revision: 1429317201 URL: https://bugs.php.net/patch-display.php?bug=55804&patch=doc-55804&revision=1429317201 Previous Comments: ------------------------------------------------------------------------ [2015-03-24 10:37:46] php at geheimeinformatie dot nl Even without an open_basedir restriction in place, the following script: <?php ini_set( "error_reporting", 2047 ); ini_set( "display_errors", 1 ); var_dump( tempnam( "/etc", "wtf-" ) ); ?> just yields the output 'string(15) "/tmp/wtf-xxxxxx"'. There's no PHP warning, or any sort of indication that the operation failed. The only way to tell the write failed is to manually verify that the file in question is actually in the specified folder. I *get* falling back to sensible defaults, but is a simple warning too much to ask? I can also verify that this is indeed documented behaviour, but quite frankly I didn't start looking for this, let's face it, this *footnote* in the docs until after I bricked multiple servers. (Running out of disk space on Linux is not pretty.) ------------------------------------------------------------------------ [2015-01-19 16:48:15] jo at feuersee dot de May I propose to clarify the documentation then, pls? It currently reads: "If the directory does not exist, tempnam() may generate a file in the system's temporary directory, and return the full path to that file, including its name." In fact it should hint the permission relation: "If the directory does not exist or is not writeable ..." And the fallback behavios should vanish in PHP7 ------------------------------------------------------------------------ [2011-09-28 09:42:28] spam2 at rhsoft dot net your definition of "easy solution" is a little bit strange how can it be easy to set a ENV-Var for 500 domains where only most of them use docroot/temp/ a smarter fallback would be the configured uploadtemp but not /tmp ------------------------------------------------------------------------ [2011-09-28 09:28:44] pajoye@php.net I was wrong about the removal, that's only for tmpfile. The rest of my comment remains (BC break and easy solution). ------------------------------------------------------------------------ [2011-09-28 09:22:29] spam2 at rhsoft dot net they are not removed or how should a stat-call in a terminal show that they are existing? anyways - they must not be created Warning: fopen() [function.fopen.php]: open_basedir restriction in effect. File(/tmp/rhcsv5f9RIs) is not within the allowed path(s): (/mnt/data/www/beta.rhsoft.net:/Volumes/dune/www-servers/phpincludes:/var/www/uploadtemp) in /mnt/data/www/beta.rhsoft.net/tempname.php on line 6 Warning: fopen(/tmp/rhcsv5f9RIs) [function.fopen.php]: failed to open stream: Operation not permitted in /mnt/data/www/beta.rhsoft.net/tempname.php on line 6 [harry@srv-rhsoft:~]$ stat /tmp/rhcsv5f9RIs Datei: „/tmp/rhcsv5f9RIs“ Größe: 0 Blöcke: 0 EA Block: 4096 reguläre leere Datei Gerät: 809h/2057d Inode: 48 Verknüpfungen: 1 Zugriff: (0600/-rw-------) Uid: ( 48/ apache) Gid: ( 48/ apache) Zugriff : 2011-09-28 08:58:01.046916064 +0200 Modifiziert: 2011-09-28 08:58:01.046916064 +0200 Geändert : 2011-09-28 08:58:01.046916064 +0200 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=55804 -- Edit this bug report at https://bugs.php.net/bug.php?id=55804&edit=1

« previous php.bugs (#192176) next »