Bug #76836 [NEW]: misleading error message if open_basedir points to inaccessable target
| From: | bugs dot php dot net at register dot conactive dot com | Date: | Sun, 02 Sep 2018 14:00:03 +0000 |
| Subject: | Bug #76836 [NEW]: misleading error message if open_basedir points to inaccessable target | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-216855@lists.php.net to get a copy of this message | ||
From: bugs dot php dot net at register dot conactive dot com
Operating system: Ubuntu 16.04
PHP version: 7.2.9
Package: Safe Mode/open_basedir
Bug Type: Bug
Bug description:misleading error message if open_basedir points to inaccessable target
Description:
------------
This is NOT a security bug! It's only a very misleading error message.
Example:
open_basedir is set to /var/vmail/ (among other directories)
/var/vmail is drwxrwx--- 9 vmail vmail 4096 Sep 2 15:13 .
user.group for fpm pool is www-data.www-data
So, user/group www-data does not have access to it.
Trying to mkdir or write (file_put_contents) within that directory fails
with message about open_basedir restriction (see below). However, this
message is not correct. It fails because of insufficient permissions. It
does NOT fail because of the open_basedir restriction!
If I change permissions to
/var/vmail is drwxrwx--x 9 vmail vmail 4096 Sep 2 15:13 .
the misleading error message goes away and the file operation succeeds
(if permissions in the target area below are correct).
Related to https://bugs.php.net/bug.php?id=69240, I suppose.
Expected result:
----------------
There should be an error message about missing permissions. There should
be NO warning about open_basedir at all in this case, as it's wrong: the
file is clearly within the allowed paths.
It would fail to enter that directory without open_basedir set as well!
It probably fails to find the dir because it's inaccessible to the pool.
I think in this case it should emit a warning "directory does not exist"
or something to that effect. But saying that x is not x in an error
message is confusing.
Actual result:
--------------
I get a warning on all kinds of file operations (tried is_dir, mkdir,
file_put_contents) that includes this text:
PHP Warning: is_dir(): open_basedir restriction in effect.
File(/var/vmail/sieve/whatever/whatever/whatever) is not within the
allowed path(s): (...:/var/vmail/sieve/:...) in ....
file_put_contents adds a second message "failed to open stream:
Operation not permitted" which might be fine, but the first warning is
still wrong. The ...dir operations get only the open_basedir warning.
--
Edit bug report at https://bugs.php.net/bug.php?id=76836&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76836&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76836&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76836&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=76836&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=76836&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=76836&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=76836&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=76836&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=76836&r=support
Expected behavior: https://bugs.php.net/fix.php?id=76836&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=76836&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=76836&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=76836&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76836&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=76836&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=76836&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=76836&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=76836&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=76836&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=76836&r=mysqlcfg