Bug #74171 [Dup]: unexpected open_basedir restriction warning
| From: | nk dot hesam+php at gmail dot com | Date: | Sun, 26 Feb 2017 16:57:05 +0000 |
| Subject: | Bug #74171 [Dup]: unexpected open_basedir restriction warning | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207570@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74171&edit=1
ID: 74171
User updated by: nk dot hesam+php at gmail dot com
Reported by: nk dot hesam+php at gmail dot com
Summary: unexpected open_basedir restriction warning
Status: Duplicate
Type: Bug
Package: Safe Mode/open_basedir
Operating System: OSX, Ubuntu
PHP Version: 5.6.30
Block user comment: N
Private report: N
New Comment:
I did search before submitting but couldn't find anything but #41518. sorry about that.
And yep everything was fine until I deployed my system on a plesk shared server with open_basedir in
action and the issue showed up. very hard to find and debug.
Previous Comments:
------------------------------------------------------------------------
[2017-02-26 15:35:36] spam2 at rhsoft dot net
and what does the "and many others" tell you?
for me it tells it's a real life problem for many developers, especially when someone dvelops
on a sunshine environment without open_basedir and finally on a server with open_basedir
opportunitic checks like file_exists('../something'); starting to flood logs for no good
reason
------------------------------------------------------------------------
[2017-02-26 15:32:58] requinix@php.net
Duplicate of bug #52065 and many others.
http://news.php.net/php.internals/86301
------------------------------------------------------------------------
[2017-02-26 15:13:33] spam2 at rhsoft dot net
it's in general a shame that you need to use @file_exists(), @is_file() and @is_dir() tu
supress warnings instead have PHP just shut up and return false if
a) it don't exist
b) the path is outside open_basdir no matter if it exists or not
b) is pretty clear because from the POV of the script it *don't exist*
------------------------------------------------------------------------
[2017-02-26 15:02:29] nk dot hesam+php at gmail dot com
Description:
------------
very similar to Bug #41518 [https://bugs.php.net/bug.php?id=41518], but happening in a much narrower
case.
consider following file structure exists:
- parent
- folder1
- image2.jpg
- file.txt
with open_basedir enabled, consider one tries to perform file_exists($filename) with $filename
within the permitted paths. three cases are presented:
- $filename = 'path/to/parent/folder1/image.jpg'
file does not exists but the containing folder (folder1) does. file_exists() returns false as
expected.
- $filename = 'path/to/parent/folder2/image.jpg'
neither file nor it's containing folder (folder2) do not exist. file_exists() returns false
as expected.
- $filename = 'path/to/parent/file.txt/image.jpg'
the target file (image.jpg) does not exist but there is a file named file.txt, in this case when
file_exists() tries to look into file.txt (it assumes it's a folder) an open_basedir
restriction warning arises. file_exists() still returns false.
same thing happens with is_file and is_dir functions.
I've checked it on PHP 5.6.30 and 7.0.12 and same thing happens on both versions.
Test script:
---------------
ini_set('open_basedir', 'path/to/parent');
file_exists('path/to/parent/folder1/image.jpg'); // returns false
file_exists('path/to/parent/folder2/image.jpg'); // returns false
file_exists('path/to/parent/file.txt/image.jpg'); // returns false and causes open_basedir
warning
Expected result:
----------------
all three cases should return false without warning. as the given $filename to file_exists()
function is located under allowed paths.
Actual result:
--------------
the third function call results in following warning:
Warning: file_exists(): open_basedir restriction in effect.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74171&edit=1