Bug #79851 [Fbk->Csd]: open_basedir no longer restricts access to http://

From: Date: Mon, 13 Jul 2020 13:28:42 +0000
Subject: Bug #79851 [Fbk->Csd]: open_basedir no longer restricts access to http://
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-228011@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79851&edit=1 ID: 79851 Updated by: sjon@php.net Reported by: sjon@php.net Summary: open_basedir no longer restricts access to http:// -Status: Feedback +Status: Closed Type: Bug Package: Filesystem function related Operating System: archLinux PHP Version: 8.0.0alpha2 Assigned To: cmb Block user comment: N Private report: N New Comment: I agree, but I think some people will be bitten by this anyway which is why it might deserve a line in UPGRADING Previous Comments: ------------------------------------------------------------------------ [2020-07-13 13:21:35] nikic@php.net Yeah, seeing how this just matches the behavior with other functions like fopen(), I don't think special action is needed. ------------------------------------------------------------------------ [2020-07-13 13:17:39] cmb@php.net > The new behavior is correct, right? In my opinion, yes. Why should open_basedir affect HTTP URLs? I don't even think this needs a special note (UPGRADING or such). It's just a bug fix, isn't it? ------------------------------------------------------------------------ [2020-07-13 12:59:01] nikic@php.net This one probably isn't PHP 8 specific, just not rolled out on earlier branches yet. It's presumably introduced by https://github.com/php/php-src/pull/5237. @cmb: The new behavior is correct, right? ------------------------------------------------------------------------ [2020-07-13 12:38:30] sjon@php.net Description: ------------ Previously open_basedir would prevent file-functions from accessing protocols such as http. It no longer does, and this change doesn't appear to be documented anywhere. This might simply need an entry in upgrading as is correct according to https://www.php.net/manual/en/function.fopen.php originally found as https://3v4l.org/oLWdo Test script: --------------- $file = 'http://www.phpcodepad.com/index.php'; $newfile = 'example.txt'; copy($file, $newfile); Expected result: ---------------- Warning: copy(): open_basedir restriction in effect. File(http://www.phpcodepad.com/index.php) is not within the allowed path(s): (/tmp:/in:/etc) in /in/oLWdo on line 5 Actual result: -------------- Warning: copy(): php_network_getaddresses: getaddrinfo failed: Temporary failure in name resolution in /in/oLWdo on line 5 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79851&edit=1

« previous php.bugs (#228011) next »