Req #37989 [Com]: Enviroment variables not availabe on exec,mail,...

From: Date: Wed, 19 Jun 2019 05:54:10 +0000
Subject: Req #37989 [Com]: Enviroment variables not availabe on exec,mail,...
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221377@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=37989&edit=1 ID: 37989 Comment by: erik at coretech dot se Reported by: david at ols dot es Summary: Enviroment variables not availabe on exec,mail,... Status: Open Type: Feature/Change Request Package: *General Issues Operating System: Linux PHP Version: 4.4.2 Block user comment: N Private report: N New Comment: You should be able to achieve this via proc_open(): Argument env: An array with the environment variables for the command that will be run, or NULL to use the same environment as the current PHP process I don't think it would be a great idea to enable this for exec() per default as it would change behaviour for existing scripts and possibly copying terminal variables and such which could break the scripts or introduce unwanted effects. /Erik Lundin Previous Comments: ------------------------------------------------------------------------ [2017-01-21 07:53:29] david at ols dot es yes, as an exmaple, having the REMOTE_ADDR user ip address will be very helpful when calling mail so the mailer could check it against spamhaus/cbl , also having REQUEST_URI available could help tracking problems in an enviroment where one has control over the mailer but not over the customer php scripts, specially when the website has been compromised or infected by malware. Will be really useful to track and limit the damage caused in such situations. ------------------------------------------------------------------------ [2017-01-20 21:06:45] heiglandreas@php.net Is this still relevant? ------------------------------------------------------------------------ [2015-12-08 12:49:03] david at ols dot es Related To: Bug #36341 ------------------------------------------------------------------------ [2006-07-03 07:42:54] david at ols dot es ok, but according to apache documentation apache setenv "Sets an environment variable, which is then passed on to CGI scripts and SSI pages" , it could be considered that those variables should also be in php enviroment, where in fact they appear to be (as they could be accesed with getenv) and that it should also be in the enviroment of programs called by php. From a strict point of view the enviroment of apache should be propagated to php and then also to programs called by php. Apache API has functions to initialize and set the enviroment but that functions are not called by the php module. In th other hand when php is run as cgi then that enviroment is correctly set which makes it more inconsistent with how it works when run as an apache module. Maybe this could be trated as a feature request rather than an bug (and i could provide a patch for the apache php module which will correctly set the enviroment). Anyway the documentation should be changed to state that the apache enviroment in not really in the real program enviroment and that is not available for programs called by php). ------------------------------------------------------------------------ [2006-07-03 06:47:28] tony2001@php.net >If PHP can access that variables via getenv() it (should) >mean that they are in the enviroment Nope. That means only that those "environment" variables are in Apache hash. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=37989 -- Edit this bug report at https://bugs.php.net/bug.php?id=37989&edit=1

« previous php.bugs (#221377) next »