Req #65386 [Com]: [summary] disable_functions / enable_functions / virtualhost...

From: Date: Thu, 16 Mar 2017 01:40:55 +0000
Subject: Req #65386 [Com]: [summary] disable_functions / enable_functions / virtualhost...
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207863@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65386&edit=1 ID: 65386 Comment by: own3mall at gmail dot com Reported by: ben dot rubson at gmail dot com Summary: [summary] disable_functions / enable_functions / virtualhost... Status: Open Type: Feature/Change Request Package: PHP options/info functions PHP Version: 5.6.7 Block user comment: N Private report: N New Comment: nginx and php-fpm work as expected in my opinion. fastcgi_param PHP_ADMIN_VALUE "disable_functions=exec,passthru,shell_exec,system,proc_open,popen"; Disables those functions on a virtual host entry in the nginx template. However, the same thing adjusted for Apache2 syntax does NOT: php_admin_value disable_functions exec,passthru,shell_exec,system,proc_open,popen I think the behavior in Apache2 should be the same as it is in nginx. I don't want to use Suhosin, and I shouldn't have to disable those functions globally in the php.ini file since some of my sites absolutely need to use those functions. Previous Comments: ------------------------------------------------------------------------ [2017-01-19 17:59:03] spam2 at rhsoft dot net oh YES! i wrote a bugreport years ago - one of the problems is/was that phpinfo() even shows the vhost setting but the functions are *not* disabled while suhosin had many years a per-host working param which worked as expected can you also please take a look at https://bugs.php.net/bug.php?id=73921 it's horrible that disabled_functions just lead to a warning where on most servers you have no access and so instead of notice that something don't run it should throw a exception which can be handeled properly ------------------------------------------------------------------------ [2017-01-19 11:26:22] ben dot rubson at gmail dot com Thank you cmb for your suggestion. I then just opened a discussion : http://marc.info/?l=php-internals&m=148482478815431&w=2 ------------------------------------------------------------------------ [2017-01-13 12:31:06] cmb@php.net It seems to me that those changes would require at least some discussion on the internals mailing list, and perhaps even an RFC, see <http://wiki.php.net/rfc/howto>. ------------------------------------------------------------------------ [2015-05-24 17:40:03] ben dot rubson at gmail dot com Hello, Any news about this please ? Thank you ! ------------------------------------------------------------------------ [2014-02-23 17:26:36] ben dot rubson at gmail dot com Hello, Any news about these requests ? - modification of disable_functions to be a PHP_INI_SYSTEM directive ; - implementation of enable_functions as a PHP_INI_SYSTEM directive ; - support of wildcards in these 2 directives. Thank you ! ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=65386 -- Edit this bug report at https://bugs.php.net/bug.php?id=65386&edit=1

« previous php.bugs (#207863) next »