Bug #71340 [NEW]: php_admin_value[error_reporting] in fpm pool conf can be bypassed in user code

From: Date: Mon, 11 Jan 2016 18:24:14 +0000
Subject: Bug #71340 [NEW]: php_admin_value[error_reporting] in fpm pool conf can be bypassed in user code
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198579@lists.php.net to get a copy of this message
From:             gpointorama at gmail dot com
Operating system: Ubuntu 14.04.3 LTS
PHP version:      7.0.2
Package:          FPM related
Bug Type:         Bug
Bug description:php_admin_value[error_reporting] in fpm pool conf can be bypassed in user code

Description:
------------
We are doing some tests before upgrading to php7 and found this change
in behavior between php5 and php7:

setting

php_admin_value[error_reporting] = E_ALL & ~E_NOTICE

in some fpm pool configuration can be bypassed in user code calling
error_reporting()

the php5 version we are using was:

PHP 5.5.9-1ubuntu4.14 (fpm-fcgi) (built: Oct 28 2015 01:38:24)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies
    with Zend OPcache v7.0.3, Copyright (c) 1999-2014, by Zend
Technologies

and the php7 one is from:

https://launchpad.net/~ondrej/+archive/ubuntu/php-7.0
PHP 7.0.2-1+deb.sury.org~trusty+1 (fpm-fcgi)
Copyright (c) 1997-2015 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2015 Zend Technologies










Test script:
---------------
error_reporting(E_ALL); //in php5 this call have no effect and
php_admin_value[error_reporting] wins over
$a = array();
echo $a['b']; //should not trigger: Notice: Undefined index: b, because
error_reporting still be E_ALL & ~E_NOTICE


-- 
Edit bug report at https://bugs.php.net/bug.php?id=71340&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=71340&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=71340&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=71340&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=71340&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=71340&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=71340&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=71340&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=71340&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=71340&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=71340&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=71340&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=71340&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=71340&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71340&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=71340&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=71340&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=71340&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71340&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=71340&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=71340&r=mysqlcfg



Thread (28 messages)

« previous php.bugs (#198579) next »