Bug #79851 [Opn]: open_basedir no longer restricts access to http://
Edit report at https://bugs.php.net/bug.php?id=79851&edit=1
ID: 79851
Updated by: nikic@php.net
Reported by: sjon@php.net
Summary: open_basedir no longer restricts access to http://
Status: Open
Type: Bug
Package: Filesystem function related
Operating System: archLinux
PHP Version: 8.0.0alpha2
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This one probably isn't PHP 8 specific, just not rolled out on earlier branches yet. It's
presumably introduced by https://github.com/php/php-src/pull/5237.
@cmb: The new behavior is correct, right?
Previous Comments:
------------------------------------------------------------------------
[2020-07-13 12:38:30] sjon@php.net
Description:
------------
Previously open_basedir would prevent file-functions from accessing protocols such as http. It no
longer does, and this change doesn't appear to be documented anywhere. This might simply need
an entry in upgrading as is correct according to https://www.php.net/manual/en/function.fopen.php
originally found as https://3v4l.org/oLWdo
Test script:
---------------
$file = 'http://www.phpcodepad.com/index.php';
$newfile = 'example.txt';
copy($file, $newfile);
Expected result:
----------------
Warning: copy(): open_basedir restriction in effect. File(http://www.phpcodepad.com/index.php) is
not within the allowed path(s): (/tmp:/in:/etc) in /in/oLWdo on line 5
Actual result:
--------------
Warning: copy(): php_network_getaddresses: getaddrinfo failed: Temporary failure in name resolution
in /in/oLWdo on line 5
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79851&edit=1
Thread (5 messages)