Bug #75212 [Com]: php_value acts like php_admin_value
| From: | spam2 at rhsoft dot net | Date: | Mon, 18 Sep 2017 17:25:40 +0000 |
| Subject: | Bug #75212 [Com]: php_value acts like php_admin_value | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-211230@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75212&edit=1
ID: 75212
Comment by: spam2 at rhsoft dot net
Reported by: remi@php.net
Summary: php_value acts like php_admin_value
Status: Closed
Type: Bug
Package: FPM related
Operating System: GNU/Linux
PHP Version: Irrelevant
Assigned To: remi
Block user comment: N
Private report: N
New Comment:
> As discussed on the PR, this may raised some unwanted
> changes in stable branch (if users occasionally have
> .user.ini files laying around, those suddenly start
> to take effect)
that's a terrible broken point of view
.user.ini files don't appear magically and users expect them to behave as they are written,
thats's the same as 'open_basedir' can't be changed anywhere outside php.ini but
is displayed (or at least was) with the local value of the vhost which leaded in my case in unwanted
security holes becaus eshell commands was intended to be only allowed by 2 out of some hundret
vhosts
frankly you can't call behave as configured a "unwanted change"
Previous Comments:
------------------------------------------------------------------------
[2017-09-18 16:11:19] remi@php.net
As discussed on the PR, this may raised some unwanted changes in stable branch (if users
occasionally have .user.ini files laying around, those suddenly start to take effect).
So this will be fixed in 7.2 only
------------------------------------------------------------------------
[2017-09-18 16:09:48] remi@php.net
Automatic comment on behalf of remi
Revision: http://git.php.net/?p=php-src.git;a=commit;h=cfc6c4d2973c795cb400435a28805a73c02d23e2
Log: Fixed Bug #75212 php_value acts like php_admin_value
------------------------------------------------------------------------
[2017-09-15 14:09:24] remi@php.net
Description:
------------
If pool configuration contains a php_admin_value directive, it is protected and cannot be modified
in .user.init: OK.
If pool configuration contains a php_value directive, it is also protected and cannot be modified in
.user.init: looks like a bug.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75212&edit=1