Bug #71340 [Com]: php_admin_value[error_reporting] in fpm pool conf can be bypassed in user code

From: Date: Sun, 20 Mar 2016 18:07:37 +0000
Subject: Bug #71340 [Com]: php_admin_value[error_reporting] in fpm pool conf can be bypassed in user code
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199970@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71340&edit=1

 ID:                 71340
 Comment by:         rabell at anchorbell dot com
 Reported by:        gpointorama at gmail dot com
 Summary:            php_admin_value[error_reporting] in fpm pool conf
                     can be bypassed in user code
 Status:             Open
 Type:               Bug
 Package:            FPM related
 Operating System:   Ubuntu 14.04.3 LTS
 PHP Version:        7.0.2
 Block user comment: N
 Private report:     N

 New Comment:

I made a change to ZEND_FUNCTION(error_reporting)in
zend_builtin_functions.c which corrects this error.
I reverted this to something based on code in previous version of PHP.
As I am not experienced in changing PHP, I cannot say if this is a good
fix, but it establishes what the problem is.

New code:
ZEND_FUNCTION(error_reporting)
{
	zval *err;
	int old_error_reporting;

#ifndef FAST_ZPP
	if (zend_parse_parameters(ZEND_NUM_ARGS(), "|z", &err) == FAILURE) {
		return;
	}
#else
	ZEND_PARSE_PARAMETERS_START(0, 1)
		Z_PARAM_OPTIONAL
		Z_PARAM_ZVAL(err)
	ZEND_PARSE_PARAMETERS_END();
#endif

	old_error_reporting = EG(error_reporting);
	if(ZEND_NUM_ARGS() != 0) {
		zend_string *key = zend_string_init("error_reporting",
sizeof("error_reporting")-1, 0);
		zend_string* value = zval_get_string(err);
		zend_alter_ini_entry(key, value, ZEND_INI_USER,
ZEND_INI_STAGE_RUNTIME);
		zend_string_release(key);
	}

	RETVAL_LONG(old_error_reporting);
}


Previous Comments:
------------------------------------------------------------------------
[2016-03-16 19:22:41] rabell at anchorbell dot com

This occurs also with php_admin_value error_reporting set from Apache config.
Problem not specific to FPM.
I also find it a considerable nuisance.

------------------------------------------------------------------------
[2016-01-28 12:24:05] gpointorama at gmail dot com

Can someone give feedback on this?

It's a problematic breaking change and is not mentioned in the migration guide or php doc.

We do shared hosting and this php_admin_value[error_reporting] config, not bypassable by user code,
give us the ability to simplify third party code management a lot.

We rely on this in production and we used it successfully with magento wordpress drupal moodle and
others without any contraindication.

php_admin_value setted ini options values should not be bypassable/changed by user code  even if the
option is error_reporting, as all previous version of php have done.

please fix this incompatible and wrong behavior in php7!

------------------------------------------------------------------------
[2016-01-11 18:24:13] gpointorama at gmail dot com

Description:
------------
We are doing some tests before upgrading to php7 and found this change in behavior between php5 and
php7:

setting

php_admin_value[error_reporting] = E_ALL & ~E_NOTICE

in some fpm pool configuration can be bypassed in user code calling error_reporting()

the php5 version we are using was:

PHP 5.5.9-1ubuntu4.14 (fpm-fcgi) (built: Oct 28 2015 01:38:24)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies
    with Zend OPcache v7.0.3, Copyright (c) 1999-2014, by Zend Technologies

and the php7 one is from:

https://launchpad.net/~ondrej/+archive/ubuntu/php-7.0
PHP 7.0.2-1+deb.sury.org~trusty+1 (fpm-fcgi)
Copyright (c) 1997-2015 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2015 Zend Technologies










Test script:
---------------
error_reporting(E_ALL); //in php5 this call have no effect and php_admin_value[error_reporting] wins
over
$a = array();
echo $a['b']; //should not trigger: Notice: Undefined index: b, because error_reporting
still be E_ALL & ~E_NOTICE



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71340&edit=1


Thread (28 messages)

« previous php.bugs (#199970) next »