Bug #77979 [Com]: open_basedir deprecation

From: Date: Wed, 08 May 2019 09:16:44 +0000
Subject: Bug #77979 [Com]: open_basedir deprecation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220770@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77979&edit=1 ID: 77979 Comment by: spam2 at rhsoft dot net Reported by: spam2 at rhsoft dot net Summary: open_basedir deprecation Status: Not a bug Type: Bug Package: Safe Mode/open_basedir PHP Version: Irrelevant Block user comment: N Private report: N New Comment: yeah, sigh https://bugs.php.net/bug.php?id=73888 until that is fixed the whole realpath cache is useless and dangerous because clearstatcache() only affects the worker process which replaced the file and requests served by exatcly that process while other workers still have their autistic cache with no programmatic way to fix it it makes no sense at all that every php process maintains it's own authistic cache Previous Comments: ------------------------------------------------------------------------ [2019-05-07 18:04:34] cmb@php.net Sigh ------------------------------------------------------------------------ [2019-05-07 10:47:19] spam2 at rhsoft dot net Description: ------------ can you guys please step back from trying to remove everything left and right in PHP 8.0? everybody knows that it's not bullet proof but it has it's value the performance penalty is only because of the hardcoded nonsense instead a ini-option we patch out of PHP because with disable_functions="symlink" the race can't happen until you fix the design of realpath cache it's worthless anyways https://bugs.php.net/bug.php?id=73888 -------- Weitergeleitete Nachricht -------- Betreff: [PHP-DEV] open_basedir? Datum: Tue, 7 May 2019 12:11:03 +0200 Von: Nikita Popov <nikita.ppv@gmail.com> An: PHP internals <internals@lists.php.net> Hi internals, The open_basedir ini setting has two significant problems: 1. It is a major performance hit, because it disables the realpath cache. 2. Many people think it is a security feature and use it as such. However, open_basedir is in reality a "best effort" mechanism, with known workarounds and more regularly being found. Especially when it comes to interactions with 3rd party libraries, enforcing open_basedir is simply impossible. What open_basedir tries to do must be implemented on the operating system level to work reliably (and of course such mechanisms exist, such as jails, chroot and friends). I wonder if it is feasible to drop this ini setting? Enforcing this doesn't really seem like any of PHP's business. If not, I think we need to at least ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77979&edit=1

« previous php.bugs (#220770) next »