Bug #71340 [Opn]: php_admin_value[error_reporting] in fpm/apache conf can be bypassed in user code

From: Date: Wed, 30 Mar 2016 11:13:18 +0000
Subject: Bug #71340 [Opn]: php_admin_value[error_reporting] in fpm/apache conf can be bypassed in user code
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200239@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71340&edit=1 ID: 71340 User updated by: gpointorama at gmail dot com Reported by: gpointorama at gmail dot com -Summary: php_admin_value[error_reporting] in fpm pool conf can be bypassed in user code +Summary: php_admin_value[error_reporting] in fpm/apache conf can be bypassed in user code Status: Open Type: Bug Package: PHP options/info functions -Operating System: Ubuntu 14.04.3 LTS +Operating System: Any -PHP Version: 7.0.2 +PHP Version: 7.0.4 Block user comment: N Private report: N New Comment: Changed OS, php version and description to reflect current status Previous Comments: ------------------------------------------------------------------------ [2016-03-30 11:11:52] gpointorama at gmail dot com Changed package category. ------------------------------------------------------------------------ [2016-03-20 18:07:36] rabell at anchorbell dot com I made a change to ZEND_FUNCTION(error_reporting)in zend_builtin_functions.c which corrects this error. I reverted this to something based on code in previous version of PHP. As I am not experienced in changing PHP, I cannot say if this is a good fix, but it establishes what the problem is. New code: ZEND_FUNCTION(error_reporting) { zval *err; int old_error_reporting; #ifndef FAST_ZPP if (zend_parse_parameters(ZEND_NUM_ARGS(), "|z", &err) == FAILURE) { return; } #else ZEND_PARSE_PARAMETERS_START(0, 1) Z_PARAM_OPTIONAL Z_PARAM_ZVAL(err) ZEND_PARSE_PARAMETERS_END(); #endif old_error_reporting = EG(error_reporting); if(ZEND_NUM_ARGS() != 0) { zend_string *key = zend_string_init("error_reporting", sizeof("error_reporting")-1, 0); zend_string* value = zval_get_string(err); zend_alter_ini_entry(key, value, ZEND_INI_USER, ZEND_INI_STAGE_RUNTIME); zend_string_release(key); } RETVAL_LONG(old_error_reporting); } ------------------------------------------------------------------------ [2016-03-16 19:22:41] rabell at anchorbell dot com This occurs also with php_admin_value error_reporting set from Apache config. Problem not specific to FPM. I also find it a considerable nuisance. ------------------------------------------------------------------------ [2016-01-28 12:24:05] gpointorama at gmail dot com Can someone give feedback on this? It's a problematic breaking change and is not mentioned in the migration guide or php doc. We do shared hosting and this php_admin_value[error_reporting] config, not bypassable by user code, give us the ability to simplify third party code management a lot. We rely on this in production and we used it successfully with magento wordpress drupal moodle and others without any contraindication. php_admin_value setted ini options values should not be bypassable/changed by user code even if the option is error_reporting, as all previous version of php have done. please fix this incompatible and wrong behavior in php7! ------------------------------------------------------------------------ [2016-01-11 18:24:13] gpointorama at gmail dot com Description: ------------ We are doing some tests before upgrading to php7 and found this change in behavior between php5 and php7: setting php_admin_value[error_reporting] = E_ALL & ~E_NOTICE in some fpm pool configuration can be bypassed in user code calling error_reporting() the php5 version we are using was: PHP 5.5.9-1ubuntu4.14 (fpm-fcgi) (built: Oct 28 2015 01:38:24) Copyright (c) 1997-2014 The PHP Group Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies with Zend OPcache v7.0.3, Copyright (c) 1999-2014, by Zend Technologies and the php7 one is from: https://launchpad.net/~ondrej/+archive/ubuntu/php-7.0 PHP 7.0.2-1+deb.sury.org~trusty+1 (fpm-fcgi) Copyright (c) 1997-2015 The PHP Group Zend Engine v3.0.0, Copyright (c) 1998-2015 Zend Technologies Test script: --------------- error_reporting(E_ALL); //in php5 this call have no effect and php_admin_value[error_reporting] wins over $a = array(); echo $a['b']; //should not trigger: Notice: Undefined index: b, because error_reporting still be E_ALL & ~E_NOTICE ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71340&edit=1

« previous php.bugs (#200239) next »