Bug #72253 [Nab->Fbk]: phpinfo shows only first block of admin_value[disable_functions]

From: Date: Mon, 23 May 2016 19:09:16 +0000
Subject: Bug #72253 [Nab->Fbk]: phpinfo shows only first block of admin_value[disable_functions]
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201246@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72253&edit=1

 ID:                 72253
 Updated by:         requinix@php.net
 Reported by:        witekfl at gazeta dot pl
 Summary:            phpinfo shows only first block of
                     admin_value[disable_functions]
-Status:             Not a bug
+Status:             Feedback
 Type:               Bug
 Package:            FPM related
 Operating System:   Linux
 PHP Version:        7.0.6
 Block user comment: N
 Private report:     N

 New Comment:

If you do
  php_admin_value[disable_functions]=sin
  php_admin_value[disable_functions]=cos
  php_admin_value[disable_functions]=tan
what does phpinfo() say, what does ini_get("disable_functions") return, and which of those
functions do/do not work?


Previous Comments:
------------------------------------------------------------------------
[2016-05-23 17:43:44] fa@php.net

Disregard my last comment.

------------------------------------------------------------------------
[2016-05-23 17:41:46] fa@php.net

reproducible on 7.0.5 CLI as well:

php -n -d "disable_functions=phpinfo" -d "disable_functions=exec" -r
"phpinfo();echo exec('ls');" | grep disable_

disable_functions => exec => exec

------------------------------------------------------------------------
[2016-05-23 14:52:02] witekfl at gazeta dot pl

php_admin_value[disable_functions] = leak                                                           
                                         
php_admin_value[disable_functions] = phpinfo                                                        
                                         
php_admin_value[disable_functions] = exec
<?php
error_reporting(E_ALL);
phpinfo();

Warning: phpinfo() has been disabled for security reasons in /home/www/info.php on line 3

Could you check it first, please?

------------------------------------------------------------------------
[2016-05-22 21:04:07] requinix@php.net

php_admin_value defines a setting that cannot be overridden. The second line is ignored because it
is attempting to override the disable_function set earlier.

disable_functions is a comma-separated list of functions. Your configuration should read
  php_admin_value[disable_functions] = curl_init,curl_close

http://php.net/manual/en/ini.core.php#ini.disable-functions

------------------------------------------------------------------------
[2016-05-22 20:45:10] witekfl at gazeta dot pl

Description:
------------
phpinfo's disable_functions displays only first block of php_admin_value[disable_functions].

Test script:
---------------
php_admin_value[disable_functions] = curl_init
php_admin_value[disable_functions] = curl_close


<?php
phpinfo();

Expected result:
----------------
phpinfo in disable_functions displays curl_init, curl_close

Actual result:
--------------
curl_init


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72253&edit=1


Thread (10 messages)

« previous php.bugs (#201246) next »