Req #65386 [Com]: [summary] disable_functions / enable_functions / virtualhost...
| From: | own3mall at gmail dot com | Date: | Thu, 16 Mar 2017 01:40:55 +0000 |
| Subject: | Req #65386 [Com]: [summary] disable_functions / enable_functions / virtualhost... | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207863@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65386&edit=1
ID: 65386
Comment by: own3mall at gmail dot com
Reported by: ben dot rubson at gmail dot com
Summary: [summary] disable_functions / enable_functions /
virtualhost...
Status: Open
Type: Feature/Change Request
Package: PHP options/info functions
PHP Version: 5.6.7
Block user comment: N
Private report: N
New Comment:
nginx and php-fpm work as expected in my opinion.
fastcgi_param PHP_ADMIN_VALUE
"disable_functions=exec,passthru,shell_exec,system,proc_open,popen";
Disables those functions on a virtual host entry in the nginx template.
However, the same thing adjusted for Apache2 syntax does NOT:
php_admin_value disable_functions exec,passthru,shell_exec,system,proc_open,popen
I think the behavior in Apache2 should be the same as it is in nginx. I don't want to use
Suhosin, and I shouldn't have to disable those functions globally in the php.ini file since
some of my sites absolutely need to use those functions.
Previous Comments:
------------------------------------------------------------------------
[2017-01-19 17:59:03] spam2 at rhsoft dot net
oh YES!
i wrote a bugreport years ago - one of the problems is/was that phpinfo() even shows the vhost
setting but the functions are *not* disabled while suhosin had many years a per-host working param
which worked as expected
can you also please take a look at https://bugs.php.net/bug.php?id=73921 it's
horrible that disabled_functions just lead to a warning where on most servers you have no access and
so instead of notice that something don't run it should throw a exception which can be handeled
properly
------------------------------------------------------------------------
[2017-01-19 11:26:22] ben dot rubson at gmail dot com
Thank you cmb for your suggestion.
I then just opened a discussion :
http://marc.info/?l=php-internals&m=148482478815431&w=2
------------------------------------------------------------------------
[2017-01-13 12:31:06] cmb@php.net
It seems to me that those changes would require at least some
discussion on the internals mailing list, and perhaps even an RFC,
see <http://wiki.php.net/rfc/howto>.
------------------------------------------------------------------------
[2015-05-24 17:40:03] ben dot rubson at gmail dot com
Hello,
Any news about this please ?
Thank you !
------------------------------------------------------------------------
[2014-02-23 17:26:36] ben dot rubson at gmail dot com
Hello,
Any news about these requests ?
- modification of disable_functions to be a PHP_INI_SYSTEM directive ;
- implementation of enable_functions as a PHP_INI_SYSTEM directive ;
- support of wildcards in these 2 directives.
Thank you !
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=65386
--
Edit this bug report at https://bugs.php.net/bug.php?id=65386&edit=1