Bug #71340 [Opn->Ana]: php_admin_value[error_reporting] in fpm/apache conf can be bypassed in user code

From: Date: Sun, 06 May 2018 13:41:50 +0000
Subject: Bug #71340 [Opn->Ana]: php_admin_value[error_reporting] in fpm/apache conf can be bypassed in user code
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215121@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71340&edit=1

 ID:                 71340
 Updated by:         requinix@php.net
 Reported by:        gpointorama at gmail dot com
 Summary:            php_admin_value[error_reporting] in fpm/apache conf
                     can be bypassed in user code
-Status:             Open
+Status:             Analyzed
 Type:               Bug
 Package:            PHP options/info functions
 Operating System:   Any
 PHP Version:        7.0
 Block user comment: N
 Private report:     N

 New Comment:

Hard to say exactly what changed between 5 and 7 to be responsible for this, but I think the change
to bring back this behavior is straightforward: in error_reporting(), only do the change if
p->modifiable allows for it. Or possibly switch to using zend_alter_ini_entry() instead.


Previous Comments:
------------------------------------------------------------------------
[2018-05-06 13:27:41] admin at inwebse dot com

Will be there any answer from php kernel developers?

------------------------------------------------------------------------
[2018-05-02 19:26:46] spam2 at rhsoft dot net

besides that fpm seems to have still a lot of issues given that it is called the recommended way to
run PHP versus a rock-stable mod_php:

"a composer module sets error_reporting(E_ALL) which breaks parts of our app due to E_NOTICE
being thrown" is no compliement for your app - in two aspects - a) it should run clean with
E_ALL and b) you must not spit out errors/warnings to the client

------------------------------------------------------------------------
[2018-05-02 19:21:08] admin at inwebse dot com

Still persists in PHP 7.2.5. When it will be fixed?

------------------------------------------------------------------------
[2016-07-09 01:34:46] php at alternize dot com

also got hit by this in php 7.0.8. 

a composer module sets error_reporting(E_ALL) which breaks parts of our app due to E_NOTICE being
thrown. previously, we could suppress those through php_admin_value[error_reporting]

------------------------------------------------------------------------
[2016-06-10 16:17:03] gpointorama at gmail dot com

the problem still persists on the latest version :( please fix this...it's a matter of a simple
"if", rabell has also found where the code should be fixed!! someone can merge that?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71340


--
Edit this bug report at https://bugs.php.net/bug.php?id=71340&edit=1


Thread (28 messages)

« previous php.bugs (#215121) next »