Bug #52312 [Com]: PHP safe_mode/open_basedir - lstat performance problem

From: Date: Sat, 05 Jan 2019 16:09:13 +0000
Subject: Bug #52312 [Com]: PHP safe_mode/open_basedir - lstat performance problem
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218804@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=52312&edit=1

 ID:                 52312
 Comment by:         wbob at buerotiger dot de
 Reported by:        v dot damore at gmail dot com
 Summary:            PHP safe_mode/open_basedir - lstat performance
                     problem
 Status:             Analyzed
 Type:               Bug
 Package:            Safe Mode/open_basedir
 Operating System:   Linux
 PHP Version:        5.2.13
 Block user comment: N
 Private report:     N

 New Comment:

as alternative to patching sources (and as it wasn't mentioned yet in this bug#) there's
https://github.com/Whissi/realpath_turbo


Previous Comments:
------------------------------------------------------------------------
[2019-01-05 15:03:53] spam2 at rhsoft dot net

and that behavior is still plain wrong which won't be changed by any documentation - hell i am
tried of such compile time crazyiness and the need to patch sources

with disable_functions="link,symlink" that security problem don't exist on shared
hosting and on shared hosting where people only have access to a CMS it donÄt exist at all to
begin with hence make it a PIP_INI_SYSTEM option

and without a shared memory the whole cache don't work as expected at all
https://bugs.php.net/bug.php?id=73887
https://bugs.php.net/bug.php?id=73888

------------------------------------------------------------------------
[2019-01-05 13:23:10] wbob at buerotiger dot de

open_basedir disabling the realpath cache is now documented in the related ini.core sections, see https://bugs.php.net/bug.php?id=77406

------------------------------------------------------------------------
[2018-03-26 04:55:59] rob dot j dot olmos at gmail dot com

At this point I think at the very least this issue should be in the docs for each of the config
sections. safe_mode, open_basedir, and realpath_cache_size sections.

------------------------------------------------------------------------
[2016-11-05 13:35:28] spam2 at rhsoft dot net

FRANKLY: why not check if "disable_functions" contains "link" and
"symlink" and in that case just use the realpath-cache as if there would not be a
open_basedir setting or even to avoid the overhead of check this add a
"realpath_cache_openbasedir" to config options where admins which disabled the link
functions can decide for themself?

------------------------------------------------------------------------
[2016-08-31 13:05:12] pierre dot renaudet at gmail dot com

We have this issue with Symfony(3.1.3), it's really poor performance with lot of stat on
file...

With the same project on Windows (IIS 7.5 - PHP 5.6.1
 With open_basedir (empty) it's take ~300-350ms for the index
 With open_basedir set (~9 path) it's take 3.5-10s for the index

I understand security problem, but why not just clear cache (before and/or after risky function)

things like that : 
--------------------
diff --git a/ext/standard/link.c b/ext/standard/link.c
index 62e7295..a844f46 100644
--- a/ext/standard/link.c
+++ b/ext/standard/link.c
@@ -158,6 +158,11 @@ PHP_FUNCTION(symlink)
 		RETURN_FALSE;
 	}
 
+	/* Reset realpath_cache when open_basedir is not null to avoid security issues */
+	if(PG(open_basedir)){
+		realpath_cache_clean();
+	}
+
 	/* For the source, an expanded path must be used (in ZTS an other thread could have changed the
CWD).
 	 * For the target the exact string given by the user must be used, relative or not, existing or
not.
 	 * The target is relative to the link itself, not to the CWD. */
@@ -206,6 +211,11 @@ PHP_FUNCTION(link)
 		RETURN_FALSE;
 	}
 
+	/* Reset realpath_cache when open_basedir is not null to avoid security issues */
+	if(PG(open_basedir)){
+		realpath_cache_clean();
+	}
+
 #ifndef ZTS
 	ret = link(topath, frompath);
 #else
 
diff --git a/ext/standard/link_win32.c b/ext/standard/link_win32.c
index 7d43162..e47e265 100644
--- a/ext/standard/link_win32.c
+++ b/ext/standard/link_win32.c
@@ -168,6 +168,12 @@ PHP_FUNCTION(symlink)
 		php_error_docref(NULL, E_WARNING, "UTF-16 conversion failed (error %d)",
GetLastError());
 		RETURN_FALSE;
 	}
+	
+	/* Reset realpath_cache when open_basedir is not null to avoid security issues */
+	if(PG(open_basedir)){
+		realpath_cache_clean();
+	}
+
 	/* For the source, an expanded path must be used (in ZTS an other thread could have changed the
CWD).
 	 * For the target the exact string given by the user must be used, relative or not, existing or
not.
 	 * The target is relative to the link itself, not to the CWD. */
@@ -223,6 +229,11 @@ PHP_FUNCTION(link)
 		RETURN_FALSE;
 	}
 
+	/* Reset realpath_cache when open_basedir is not null to avoid security issues */
+	if(PG(open_basedir)){
+		realpath_cache_clean();
+	}
+
 #ifndef ZTS
 	ret = CreateHardLinkA(topath, frompath, NULL);
 #else
 
diff --git a/main/main.c b/main/main.c
index bb98f27..7e5904e 100644
--- a/main/main.c
+++ b/main/main.c
@@ -2222,7 +2222,7 @@ int php_module_startup(sapi_module_struct *sf, zend_module_entry
*additional_mod
 
 	/* Disable realpath cache if an open_basedir is set */
 	if (PG(open_basedir) && *PG(open_basedir)) {
-		CWDG(realpath_cache_size_limit) = 0;
+		/* CWDG(realpath_cache_size_limit) = 0; */
 	}
 
 	/* initialize stream wrappers registry
--------------

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=52312


--
Edit this bug report at https://bugs.php.net/bug.php?id=52312&edit=1


Thread (64 messages)

« previous php.bugs (#218804) next »