Req #34663 [Fbk->NoF]: Patch to get around apache not expanding %0 when passed open_basedir in vhost

From: Date: Sun, 29 Jan 2017 04:22:44 +0000
Subject: Req #34663 [Fbk->NoF]: Patch to get around apache not expanding %0 when passed open_basedir in vhost
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207017@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=34663&edit=1 ID: 34663 Updated by: php-bugs@lists.php.net Reported by: php-bugs at antispam dot nerds dot org dot uk Summary: Patch to get around apache not expanding %0 when passed open_basedir in vhost -Status: Feedback +Status: No Feedback Type: Feature/Change Request Package: *General Issues Operating System: FreeBSD PHP Version: 5.0.5 Private report: N New Comment: No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. Previous Comments: ------------------------------------------------------------------------ [2017-01-20 20:41:33] heiglandreas@php.net Is this still relevant? ------------------------------------------------------------------------ [2005-09-27 20:22:37] php-bugs at antispam dot nerds dot org dot uk Description: ------------ There are often cases where apache users with php5 installed will want to use dynamic vhosts (not least because it's in the apache docs), which leads to something like this: <VirtualHost 82.70.196.65:80> VirtualDocumentRoot /data/www/%0 ServerName %0 php_admin_value open_basedir %0 </VirtualHost> Unfortunately apache is naughty and doesn't expand the %0 on the php_admin_value line, which means that restricting the directories that php has access to is a pain! This I know is an apache problem, rather than a php one, however I found a patch on a forum (http://www.phpbuilder.com/lists/php-developer-list/2000101/0994.php) that gets around this nicely, and I just tweaked it to work in php5 (I'm not trying to claim any credit away from the original author, I just like the feature!). I figured this was posted a long time ago, if he was going to submit it - he would have by now. Basically it just adds a keyword of VIRTUAL_DOCUMENT_ROOT, which has essentially the same end result, as it causes the fopen wrapper to expand it to the VirtualDocumentRoot. Patch included at the "Reproduce Code" Reproduce code: --------------- --- main/fopen_wrappers.c.orig Sun Sep 25 22:25:20 2005 +++ main/fopen_wrappers.c Sun Sep 25 22:28:40 2005 @@ -95,8 +95,18 @@ char resolved_name[MAXPATHLEN]; char resolved_basedir[MAXPATHLEN]; char local_open_basedir[MAXPATHLEN]; + char *local_open_basedir_sub; /* Substring pointer for strstr */ int resolved_basedir_len; int resolved_name_len; + + if ((strcmp(PG(open_basedir), "VIRTUAL_DOCUMENT_ROOT") == 0) && + SG(request_info).path_translated && *SG(request_info).path_translated ) { + + strlcpy(local_open_basedir, SG(request_info).path_translated, sizeof(local_open_basedir)); + local_open_basedir_sub=strstr(local_open_basedir,SG(request_info).request_uri); + /* Now insert null to break apart the string */ + if (local_open_basedir_sub) *local_open_basedir_sub = '\0'; + } else /* Special case basedir==".": Use script-directory */ if (strcmp(basedir, ".") || !VCWD_GETCWD(local_open_basedir, MAXPATHLEN)) { ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=34663&edit=1

« previous php.bugs (#207017) next »