Edit report at https://bugs.php.net/bug.php?id=71340&edit=1
ID: 71340
User updated by: gpointorama at gmail dot com
Reported by: gpointorama at gmail dot com
Summary: php_admin_value[error_reporting] in fpm pool conf
can be bypassed in user code
Status: Open
Type: Bug
-Package: FPM related
+Package: PHP options/info functions
Operating System: Ubuntu 14.04.3 LTS
PHP Version: 7.0.2
Block user comment: N
Private report: N
New Comment:
Changed package category.
Previous Comments:
------------------------------------------------------------------------
[2016-03-20 18:07:36] rabell at anchorbell dot com
I made a change to ZEND_FUNCTION(error_reporting)in
zend_builtin_functions.c which corrects this error.
I reverted this to something based on code in previous version of PHP.
As I am not experienced in changing PHP, I cannot say if this is a good
fix, but it establishes what the problem is.
New code:
ZEND_FUNCTION(error_reporting)
{
zval *err;
int old_error_reporting;
#ifndef FAST_ZPP
if (zend_parse_parameters(ZEND_NUM_ARGS(), "|z", &err) == FAILURE) {
return;
}
#else
ZEND_PARSE_PARAMETERS_START(0, 1)
Z_PARAM_OPTIONAL
Z_PARAM_ZVAL(err)
ZEND_PARSE_PARAMETERS_END();
#endif
old_error_reporting = EG(error_reporting);
if(ZEND_NUM_ARGS() != 0) {
zend_string *key = zend_string_init("error_reporting",
sizeof("error_reporting")-1, 0);
zend_string* value = zval_get_string(err);
zend_alter_ini_entry(key, value, ZEND_INI_USER,
ZEND_INI_STAGE_RUNTIME);
zend_string_release(key);
}
RETVAL_LONG(old_error_reporting);
}
------------------------------------------------------------------------
[2016-03-16 19:22:41] rabell at anchorbell dot com
This occurs also with php_admin_value error_reporting set from Apache config.
Problem not specific to FPM.
I also find it a considerable nuisance.
------------------------------------------------------------------------
[2016-01-28 12:24:05] gpointorama at gmail dot com
Can someone give feedback on this?
It's a problematic breaking change and is not mentioned in the migration guide or php doc.
We do shared hosting and this php_admin_value[error_reporting] config, not bypassable by user code,
give us the ability to simplify third party code management a lot.
We rely on this in production and we used it successfully with magento wordpress drupal moodle and
others without any contraindication.
php_admin_value setted ini options values should not be bypassable/changed by user code even if the
option is error_reporting, as all previous version of php have done.
please fix this incompatible and wrong behavior in php7!
------------------------------------------------------------------------
[2016-01-11 18:24:13] gpointorama at gmail dot com
Description:
------------
We are doing some tests before upgrading to php7 and found this change in behavior between php5 and
php7:
setting
php_admin_value[error_reporting] = E_ALL & ~E_NOTICE
in some fpm pool configuration can be bypassed in user code calling error_reporting()
the php5 version we are using was:
PHP 5.5.9-1ubuntu4.14 (fpm-fcgi) (built: Oct 28 2015 01:38:24)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies
with Zend OPcache v7.0.3, Copyright (c) 1999-2014, by Zend Technologies
and the php7 one is from:
https://launchpad.net/~ondrej/+archive/ubuntu/php-7.0
PHP 7.0.2-1+deb.sury.org~trusty+1 (fpm-fcgi)
Copyright (c) 1997-2015 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2015 Zend Technologies
Test script:
---------------
error_reporting(E_ALL); //in php5 this call have no effect and php_admin_value[error_reporting] wins
over
$a = array();
echo $a['b']; //should not trigger: Notice: Undefined index: b, because error_reporting
still be E_ALL & ~E_NOTICE
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71340&edit=1