Bug #46378 [Com]: IIS7 FastCGI - upload_tmp_dir not working correctly

From: Date: Wed, 03 May 2017 15:09:06 +0000
Subject: Bug #46378 [Com]: IIS7 FastCGI - upload_tmp_dir not working correctly
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208941@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=46378&edit=1

 ID:                 46378
 Comment by:         andreshm1 at gmail dot com
 Reported by:        tomas dot hlavacek at telekomaustria dot cz
 Summary:            IIS7 FastCGI - upload_tmp_dir not working correctly
 Status:             Not a bug
 Type:               Bug
 Package:            *Configuration Issues
 Operating System:   Windows Server 2008
 PHP Version:        5.2.6
 Block user comment: N
 Private report:     N

 New Comment:

PHP is ignoring this because of one  setting on APPLICATION POOLS. 
It's not php-cgi nor php.ini.
go to the application pool of the website experiencing the issue:
1. right click 
2. select advanced settings
3. scroll to LOAD USER PROFILE and set it to FALSE.

that did the trick for me.


Previous Comments:
------------------------------------------------------------------------
[2013-01-19 17:16:46] pajoye@php.net

You need read attributes on any parent directories.

------------------------------------------------------------------------
[2013-01-19 16:45:26] bigtrend at gmx dot us

In addition can add that the following permissions exactly are required for 
IIS_IUSRS to the PARENT folder:
1. Traverse folder/Execute file
2. List folder/ read data
3. Write attributes
4. Write extended attributes

It is strange, but "read attributes" is not required and also "create file/write 
data" is not required as well.

Hope it will help to protect your servers from the granting too many permissions 
for "anonymous" system accounts.

------------------------------------------------------------------------
[2012-02-11 16:07:47] julientld at free dot fr

Hi Pierre Joye,

I have the same problem with an IIS 6 server with PHP 5.3.10 and FastCGI 1.5. I want to use a custom
temp directory for php file uploads.

If I set upload_tmp_dir=D:\Temp\ and set read and write acls for the user IUSR on the Temp
directory, upload fails.

As said by tomas, if we want the upload to function, the acls must also be set on the parent
directory (D:\). Obviously, I do not want to give IUSR write acls to the whole partition !!

For the moment, I have created a sub-directory for php uploads (D:\Temp\php\). I have given IUSR
acls on \Temp and \php directories (not D:\) and uploads run fine now.

But I would like to understand this phenomenon. If PHP can't write in a directory if the parent
directory does not have also same acls, it is a specific behavior related to PHP or it is a Windows
problem ?

For me it is a bug. It has no sense to be forced to give acls also to the parent directory...

Thanks for your clarifications ;)

Julien

------------------------------------------------------------------------
[2008-10-24 13:04:27] pajoye@php.net

Not a bug > bogus


------------------------------------------------------------------------
[2008-10-24 12:51:07] tomas dot hlavacek at telekomaustria dot cz

Finally, I found the problem. 

Listing on E: must be allowed for IIS_IUSRS:


E:\>icacls e:
e: NT AUTHORITY\SYSTEM:(OI)(CI)(F)
   BUILTIN\Administrators:(OI)(CI)(F)
   BUILTIN\IIS_IUSRS:(S,RD)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=46378


--
Edit this bug report at https://bugs.php.net/bug.php?id=46378&edit=1


Thread (7 messages)

« previous php.bugs (#208941) next »