Bug #77979 [Com]: open_basedir deprecation
| From: | spam2 at rhsoft dot net | Date: | Wed, 08 May 2019 09:16:44 +0000 |
| Subject: | Bug #77979 [Com]: open_basedir deprecation | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220770@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77979&edit=1
ID: 77979
Comment by: spam2 at rhsoft dot net
Reported by: spam2 at rhsoft dot net
Summary: open_basedir deprecation
Status: Not a bug
Type: Bug
Package: Safe Mode/open_basedir
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
yeah, sigh
https://bugs.php.net/bug.php?id=73888
until that is fixed the whole realpath cache is useless and dangerous because clearstatcache() only
affects the worker process which replaced the file and requests served by exatcly that process while
other workers still have their autistic cache with no programmatic way to fix it
it makes no sense at all that every php process maintains it's own authistic cache
Previous Comments:
------------------------------------------------------------------------
[2019-05-07 18:04:34] cmb@php.net
Sigh
------------------------------------------------------------------------
[2019-05-07 10:47:19] spam2 at rhsoft dot net
Description:
------------
can you guys please step back from trying to remove everything left and right in PHP 8.0?
everybody knows that it's not bullet proof but it has it's value
the performance penalty is only because of the hardcoded nonsense instead a ini-option we patch out
of PHP because with disable_functions="symlink" the race can't happen
until you fix the design of realpath cache it's worthless anyways
https://bugs.php.net/bug.php?id=73888
-------- Weitergeleitete Nachricht --------
Betreff: [PHP-DEV] open_basedir?
Datum: Tue, 7 May 2019 12:11:03 +0200
Von: Nikita Popov <nikita.ppv@gmail.com>
An: PHP internals <internals@lists.php.net>
Hi internals,
The open_basedir ini setting has two significant problems:
1. It is a major performance hit, because it disables the realpath cache.
2. Many people think it is a security feature and use it as such. However,
open_basedir is in reality a "best effort" mechanism, with known
workarounds and more regularly being found. Especially when it comes to
interactions with 3rd party libraries, enforcing open_basedir is simply
impossible.
What open_basedir tries to do must be implemented on the operating system
level to work reliably (and of course such mechanisms exist, such as jails,
chroot and friends).
I wonder if it is feasible to drop this ini setting? Enforcing this doesn't
really seem like any of PHP's business. If not, I think we need to at least
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77979&edit=1