Bug #52312 [Com]: PHP safe_mode/open_basedir - lstat performance problem

From: Date: Sat, 05 Jan 2019 16:16:54 +0000
Subject: Bug #52312 [Com]: PHP safe_mode/open_basedir - lstat performance problem
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218805@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=52312&edit=1

 ID:                 52312
 Comment by:         spam2 at rhsoft dot net
 Reported by:        v dot damore at gmail dot com
 Summary:            PHP safe_mode/open_basedir - lstat performance
                     problem
 Status:             Analyzed
 Type:               Bug
 Package:            Safe Mode/open_basedir
 Operating System:   Linux
 PHP Version:        5.2.13
 Block user comment: N
 Private report:     N

 New Comment:

out-of-tree extensions are always a problem when it comes to minor nd major updates even even the
stuff on pecl.php.net is to avoid whenever possible

"Instead of setting open_basedir you will set realpath_turbo.open_basedir" is a crude hack
which requires you to touch each and every vhost and that all because stubborn decisions for no gain

----------------------------------
[builduser@testserver:/rpmbuild/SOURCES]$ cat php-72-realpath-cache-openbasedir.patch
--- php-7.1.9-original/main/main.c      2017-08-16 18:06:53.000000000 +0200
+++ php-7.1.9-patched/main/main.c       2017-08-17 14:11:05.827653357 +0200
@@ -1646,9 +1646,9 @@
                }

                /* Disable realpath cache if an open_basedir is set */
-               if (PG(open_basedir) && *PG(open_basedir)) {
-                       CWDG(realpath_cache_size_limit) = 0;
-               }
+               /* if (PG(open_basedir) && *PG(open_basedir)) { */
+               /*      CWDG(realpath_cache_size_limit) = 0; */
+               /*}*/

                if (PG(expose_php)) {
                        sapi_add_header(SAPI_PHP_VERSION_HEADER, sizeof(SAPI_PHP_VERSION_HEADER)-1,
1);
@@ -2236,9 +2236,9 @@
 #endif

        /* Disable realpath cache if an open_basedir is set */
-       if (PG(open_basedir) && *PG(open_basedir)) {
-               CWDG(realpath_cache_size_limit) = 0;
-       }
+       /*if (PG(open_basedir) && *PG(open_basedir)) { */
+       /*      CWDG(realpath_cache_size_limit) = 0;*/
+       /*}*/

        /* initialize stream wrappers registry
         * (this uses configuration parameters from php.ini)
----------------------------------
[builduser@testserver:/rpmbuild/SOURCES]$ cat php-73-realpath-cache-openbasedir.patch
--- php-7.3.0-original/main/main.c      2018-07-31 13:33:48.000000000 +0200
+++ php-7.3.0-patched/main/main.c       2018-07-31 14:01:15.144001078 +0200
@@ -1798,9 +1798,9 @@
                }

                /* Disable realpath cache if an open_basedir is set */
-               if (PG(open_basedir) && *PG(open_basedir)) {
-                       CWDG(realpath_cache_size_limit) = 0;
-               }
+               /*if (PG(open_basedir) && *PG(open_basedir)) { */
+               /*      CWDG(realpath_cache_size_limit) = 0; */
+               /*}*/

                if (PG(expose_php)) {
                        sapi_add_header(SAPI_PHP_VERSION_HEADER, sizeof(SAPI_PHP_VERSION_HEADER)-1,
1);
@@ -2292,9 +2292,9 @@
 #endif

        /* Disable realpath cache if an open_basedir is set */
-       if (PG(open_basedir) && *PG(open_basedir)) {
-               CWDG(realpath_cache_size_limit) = 0;
-       }
+       /*if (PG(open_basedir) && *PG(open_basedir)) { */
+       /*      CWDG(realpath_cache_size_limit) = 0; */
+       /*}*/

        PG(have_called_openlog) = 0;


Previous Comments:
------------------------------------------------------------------------
[2019-01-05 16:09:13] wbob at buerotiger dot de

as alternative to patching sources (and as it wasn't mentioned yet in this bug#) there's
https://github.com/Whissi/realpath_turbo

------------------------------------------------------------------------
[2019-01-05 15:03:53] spam2 at rhsoft dot net

and that behavior is still plain wrong which won't be changed by any documentation - hell i am
tried of such compile time crazyiness and the need to patch sources

with disable_functions="link,symlink" that security problem don't exist on shared
hosting and on shared hosting where people only have access to a CMS it donÄt exist at all to
begin with hence make it a PIP_INI_SYSTEM option

and without a shared memory the whole cache don't work as expected at all
https://bugs.php.net/bug.php?id=73887
https://bugs.php.net/bug.php?id=73888

------------------------------------------------------------------------
[2019-01-05 13:23:10] wbob at buerotiger dot de

open_basedir disabling the realpath cache is now documented in the related ini.core sections, see https://bugs.php.net/bug.php?id=77406

------------------------------------------------------------------------
[2018-03-26 04:55:59] rob dot j dot olmos at gmail dot com

At this point I think at the very least this issue should be in the docs for each of the config
sections. safe_mode, open_basedir, and realpath_cache_size sections.

------------------------------------------------------------------------
[2016-11-05 13:35:28] spam2 at rhsoft dot net

FRANKLY: why not check if "disable_functions" contains "link" and
"symlink" and in that case just use the realpath-cache as if there would not be a
open_basedir setting or even to avoid the overhead of check this add a
"realpath_cache_openbasedir" to config options where admins which disabled the link
functions can decide for themself?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=52312


--
Edit this bug report at https://bugs.php.net/bug.php?id=52312&edit=1


Thread (64 messages)

« previous php.bugs (#218805) next »