Bug #74171 [NEW]: unexpected open_basedir restriction warning
| From: | nk dot hesam+php at gmail dot com | Date: | Sun, 26 Feb 2017 15:02:32 +0000 |
| Subject: | Bug #74171 [NEW]: unexpected open_basedir restriction warning | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-207566@lists.php.net to get a copy of this message | ||
From: nk dot hesam+php at gmail dot com
Operating system: OSX, Ubuntu
PHP version: 5.6.30
Package: Safe Mode/open_basedir
Bug Type: Bug
Bug description:unexpected open_basedir restriction warning
Description:
------------
very similar to Bug #41518 [https://bugs.php.net/bug.php?id=41518], but
happening in a much narrower case.
consider following file structure exists:
- parent
- folder1
- image2.jpg
- file.txt
with open_basedir enabled, consider one tries to perform
file_exists($filename) with $filename within the permitted paths. three
cases are presented:
- $filename = 'path/to/parent/folder1/image.jpg'
file does not exists but the containing folder (folder1) does.
file_exists() returns false as expected.
- $filename = 'path/to/parent/folder2/image.jpg'
neither file nor it's containing folder (folder2) do not exist.
file_exists() returns false as expected.
- $filename = 'path/to/parent/file.txt/image.jpg'
the target file (image.jpg) does not exist but there is a file named
file.txt, in this case when file_exists() tries to look into file.txt
(it assumes it's a folder) an open_basedir restriction warning arises.
file_exists() still returns false.
same thing happens with is_file and is_dir functions.
I've checked it on PHP 5.6.30 and 7.0.12 and same thing happens on both
versions.
Test script:
---------------
ini_set('open_basedir', 'path/to/parent');
file_exists('path/to/parent/folder1/image.jpg'); // returns false
file_exists('path/to/parent/folder2/image.jpg'); // returns false
file_exists('path/to/parent/file.txt/image.jpg'); // returns false and
causes open_basedir warning
Expected result:
----------------
all three cases should return false without warning. as the given
$filename to file_exists() function is located under allowed paths.
Actual result:
--------------
the third function call results in following warning:
Warning: file_exists(): open_basedir restriction in effect.
--
Edit bug report at https://bugs.php.net/bug.php?id=74171&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74171&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74171&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74171&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74171&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74171&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74171&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74171&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74171&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74171&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74171&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74171&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74171&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74171&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74171&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74171&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74171&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74171&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74171&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74171&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74171&r=mysqlcfg