Bug #71340 [Opn]: php_admin_value[error_reporting] in fpm/apache conf can be bypassed in user code

From: Date: Wed, 30 Mar 2016 11:24:44 +0000
Subject: Bug #71340 [Opn]: php_admin_value[error_reporting] in fpm/apache conf can be bypassed in user code
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200241@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71340&edit=1

 ID:                 71340
 User updated by:    gpointorama at gmail dot com
 Reported by:        gpointorama at gmail dot com
-Summary:            php_admin_value[error_reporting] in fpm/apache conf
                     should not be overridable by
+Summary:            php_admin_value[error_reporting] in fpm/apache conf
                     can be bypassed in user code
 Status:             Open
 Type:               Bug
 Package:            PHP options/info functions
 Operating System:   Any
 PHP Version:        7.0.4
 Block user comment: N
 Private report:     N

 New Comment:

Restored summary, i hate the 60 character limit, too restrictive!


Previous Comments:
------------------------------------------------------------------------
[2016-03-30 11:21:03] gpointorama at gmail dot com

Changed summary to better reflect the problem

------------------------------------------------------------------------
[2016-03-30 11:13:17] gpointorama at gmail dot com

Changed OS, php version and description to reflect current status

------------------------------------------------------------------------
[2016-03-30 11:11:52] gpointorama at gmail dot com

Changed package category.

------------------------------------------------------------------------
[2016-03-20 18:07:36] rabell at anchorbell dot com

I made a change to ZEND_FUNCTION(error_reporting)in
zend_builtin_functions.c which corrects this error.
I reverted this to something based on code in previous version of PHP.
As I am not experienced in changing PHP, I cannot say if this is a good
fix, but it establishes what the problem is.

New code:
ZEND_FUNCTION(error_reporting)
{
	zval *err;
	int old_error_reporting;

#ifndef FAST_ZPP
	if (zend_parse_parameters(ZEND_NUM_ARGS(), "|z", &err) == FAILURE) {
		return;
	}
#else
	ZEND_PARSE_PARAMETERS_START(0, 1)
		Z_PARAM_OPTIONAL
		Z_PARAM_ZVAL(err)
	ZEND_PARSE_PARAMETERS_END();
#endif

	old_error_reporting = EG(error_reporting);
	if(ZEND_NUM_ARGS() != 0) {
		zend_string *key = zend_string_init("error_reporting",
sizeof("error_reporting")-1, 0);
		zend_string* value = zval_get_string(err);
		zend_alter_ini_entry(key, value, ZEND_INI_USER,
ZEND_INI_STAGE_RUNTIME);
		zend_string_release(key);
	}

	RETVAL_LONG(old_error_reporting);
}

------------------------------------------------------------------------
[2016-03-16 19:22:41] rabell at anchorbell dot com

This occurs also with php_admin_value error_reporting set from Apache config.
Problem not specific to FPM.
I also find it a considerable nuisance.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71340


--
Edit this bug report at https://bugs.php.net/bug.php?id=71340&edit=1


Thread (28 messages)

« previous php.bugs (#200241) next »