Bug #76836 [NEW]: misleading error message if open_basedir points to inaccessable target

From: Date: Sun, 02 Sep 2018 14:00:03 +0000
Subject: Bug #76836 [NEW]: misleading error message if open_basedir points to inaccessable target
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-216855@lists.php.net to get a copy of this message
From: bugs dot php dot net at register dot conactive dot com Operating system: Ubuntu 16.04 PHP version: 7.2.9 Package: Safe Mode/open_basedir Bug Type: Bug Bug description:misleading error message if open_basedir points to inaccessable target Description: ------------ This is NOT a security bug! It's only a very misleading error message. Example: open_basedir is set to /var/vmail/ (among other directories) /var/vmail is drwxrwx--- 9 vmail vmail 4096 Sep 2 15:13 . user.group for fpm pool is www-data.www-data So, user/group www-data does not have access to it. Trying to mkdir or write (file_put_contents) within that directory fails with message about open_basedir restriction (see below). However, this message is not correct. It fails because of insufficient permissions. It does NOT fail because of the open_basedir restriction! If I change permissions to /var/vmail is drwxrwx--x 9 vmail vmail 4096 Sep 2 15:13 . the misleading error message goes away and the file operation succeeds (if permissions in the target area below are correct). Related to https://bugs.php.net/bug.php?id=69240, I suppose. Expected result: ---------------- There should be an error message about missing permissions. There should be NO warning about open_basedir at all in this case, as it's wrong: the file is clearly within the allowed paths. It would fail to enter that directory without open_basedir set as well! It probably fails to find the dir because it's inaccessible to the pool. I think in this case it should emit a warning "directory does not exist" or something to that effect. But saying that x is not x in an error message is confusing. Actual result: -------------- I get a warning on all kinds of file operations (tried is_dir, mkdir, file_put_contents) that includes this text: PHP Warning: is_dir(): open_basedir restriction in effect. File(/var/vmail/sieve/whatever/whatever/whatever) is not within the allowed path(s): (...:/var/vmail/sieve/:...) in .... file_put_contents adds a second message "failed to open stream: Operation not permitted" which might be fine, but the first warning is still wrong. The ...dir operations get only the open_basedir warning. -- Edit bug report at https://bugs.php.net/bug.php?id=76836&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76836&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76836&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76836&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=76836&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=76836&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=76836&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=76836&r=needscript Try newer version: https://bugs.php.net/fix.php?id=76836&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=76836&r=support Expected behavior: https://bugs.php.net/fix.php?id=76836&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=76836&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=76836&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=76836&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76836&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=76836&r=dst IIS Stability: https://bugs.php.net/fix.php?id=76836&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=76836&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=76836&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=76836&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=76836&r=mysqlcfg

« previous php.bugs (#216855) next »