Req #77413 [NEW]: .ini function to disable use of opcache_reset();

From: Date: Sat, 05 Jan 2019 12:38:45 +0000
Subject: Req #77413 [NEW]: .ini function to disable use of opcache_reset();
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218797@lists.php.net to get a copy of this message
From:             post at minhost dot no
Operating system: CentOS 7.x
PHP version:      7.2.13
Package:          opcache
Bug Type:         Feature/Change Request
Bug description:.ini function to disable use of opcache_reset();

Description:
------------
We are running shared hosting servers with many different customers and
sites on each dedicated server. We allocate enough memory to opcache so
that all customers php scripts is cached in opcache.

The problem is that our shared hosting customers is able to upload a php
script with the following code to empty opcache for ALL customers on
that same server:

<?php
opcache_reset();

Further there is nothing stopping any customers from doing this as
frequently as they like. It is a big problem that one single customer
can empty the entire opcache for all other customers on the same
server.

Please add a new .ini function to disable the php code opcache_reset();
from being able to execute, so that we can disable this completely in
opcache.ini/php.ini - We do not need to empty opcache by using this PHP
code. opcache is emptied when we reload php-fpm, and that is enough for
us.

The new .ini function should be added to this page:
http://php.net/manual/en/opcache.configuration.php
- Suggestion for
naming of the .ini function: opcache.disable.reset= 0 or 1

Please appreciate that it is problematic for shared hosting providers
that any users on a server can run opcache_reset(); in a php script to
empty opcache for all other customers on the same server.


-- 
Edit bug report at https://bugs.php.net/bug.php?id=77413&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=77413&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=77413&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=77413&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=77413&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=77413&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=77413&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=77413&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=77413&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=77413&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=77413&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=77413&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=77413&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=77413&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77413&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=77413&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=77413&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=77413&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77413&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=77413&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=77413&r=mysqlcfg



Thread (6 messages)

« previous php.bugs (#218797) next »