Req #77413 [Wfx->Csd]: .ini function to disable use of opcache_reset();
Edit report at https://bugs.php.net/bug.php?id=77413&edit=1
ID: 77413
User updated by: post at minhost dot no
Reported by: post at minhost dot no
Summary: .ini function to disable use of opcache_reset();
-Status: Wont fix
+Status: Closed
Type: Feature/Change Request
Package: opcache
Operating System: CentOS 7.x
PHP Version: 7.2.13
Block user comment: N
Private report: N
New Comment:
Thank you. I feel stupid I never thought of that. :) Changing the status to closed.
Previous Comments:
------------------------------------------------------------------------
[2019-01-05 13:01:04] requinix@php.net
This is the sort of situation that disable_functions is designed for.
http://php.net/manual/en/ini.core.php#ini.disable-functions
------------------------------------------------------------------------
[2019-01-05 12:38:45] post at minhost dot no
Description:
------------
We are running shared hosting servers with many different customers and sites on each dedicated
server. We allocate enough memory to opcache so that all customers php scripts is cached in opcache.
The problem is that our shared hosting customers is able to upload a php script with the following
code to empty opcache for ALL customers on that same server:
<?php
opcache_reset();
Further there is nothing stopping any customers from doing this as frequently as they like. It is a
big problem that one single customer can empty the entire opcache for all other customers on the
same server.
Please add a new .ini function to disable the php code opcache_reset(); from being able to execute,
so that we can disable this completely in opcache.ini/php.ini - We do not need to empty opcache by
using this PHP code. opcache is emptied when we reload php-fpm, and that is enough for us.
The new .ini function should be added to this page: http://php.net/manual/en/opcache.configuration.php
- Suggestion for naming of the .ini function: opcache.disable.reset= 0 or 1
Please appreciate that it is problematic for shared hosting providers that any users on a server can
run opcache_reset(); in a php script to empty opcache for all other customers on the same server.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77413&edit=1
Thread (6 messages)