Req #77413 [Com]: .ini function to disable use of opcache_reset();

From: Date: Sat, 05 Jan 2019 14:57:05 +0000
Subject: Req #77413 [Com]: .ini function to disable use of opcache_reset();
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218801@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77413&edit=1

 ID:                 77413
 Comment by:         spam2 at rhsoft dot net
 Reported by:        post at minhost dot no
 Summary:            .ini function to disable use of opcache_reset();
 Status:             Closed
 Type:               Feature/Change Request
 Package:            opcache
 Operating System:   CentOS 7.x
 PHP Version:        7.2.13
 Block user comment: N
 Private report:     N

 New Comment:

besides that you likely want opcache.restrict_api = "/usr/share/php/opcache.php" when you
run shared hosting and didn't know about "disable_functions" you have far bigger
problems than clearing a cache which populates itself again

disable_functions = "get_browser, apcu_cache_info, apcu_clear_cache, apcu_sma_info,
apache_child_terminate, chown, dl, exec, fileinode, get_current_user, getmypid, getmyuid, getrusage,
highlight_file, link, mail, openlog, passthru, pclose, pcntl_alarm, pcntl_errno, pcntl_exec,
pcntl_fork, pcntl_get_last_error, pcntl_getpriority, pcntl_setpriority, pcntl_signal_dispatch,
pcntl_signal, pcntl_sigprocmask, pcntl_sigtimedwait, pcntl_sigwaitinfo, pcntl_strerror, pcntl_wait,
pcntl_waitpid, pcntl_wexitstatus, pcntl_wifexited, pcntl_wifsignaled, pcntl_wifstopped,
pcntl_wstopsig, pcntl_wtermsig, pfsockopen, popen, posix_kill, posix_mkfifo, posix_setpgid,
posix_setsid, posix_setuid, proc_close, proc_get_status, proc_nice, proc_open, proc_terminate,
shell_exec, show_source, socket_accept, socket_bind, symlink, syslog, system"


Previous Comments:
------------------------------------------------------------------------
[2019-01-05 13:12:29] post at minhost dot no

Thank you. I feel stupid I never thought of that. :) Changing the status to closed.

------------------------------------------------------------------------
[2019-01-05 13:01:04] requinix@php.net

This is the sort of situation that disable_functions is designed for.
http://php.net/manual/en/ini.core.php#ini.disable-functions

------------------------------------------------------------------------
[2019-01-05 12:38:45] post at minhost dot no

Description:
------------
We are running shared hosting servers with many different customers and sites on each dedicated
server. We allocate enough memory to opcache so that all customers php scripts is cached in opcache.

The problem is that our shared hosting customers is able to upload a php script with the following
code to empty opcache for ALL customers on that same server:

<?php
opcache_reset();

Further there is nothing stopping any customers from doing this as frequently as they like. It is a
big problem that one single customer can empty the entire opcache for all other customers on the
same server.

Please add a new .ini function to disable the php code opcache_reset(); from being able to execute,
so that we can disable this completely in opcache.ini/php.ini - We do not need to empty opcache by
using this PHP code. opcache is emptied when we reload php-fpm, and that is enough for us.

The new .ini function should be added to this page: http://php.net/manual/en/opcache.configuration.php
- Suggestion for naming of the .ini function: opcache.disable.reset= 0 or 1

Please appreciate that it is problematic for shared hosting providers that any users on a server can
run opcache_reset(); in a php script to empty opcache for all other customers on the same server.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77413&edit=1


Thread (6 messages)

« previous php.bugs (#218801) next »