Req #53263 [Com]: Allow realpath cache to function even with open_basedir enabled
| From: | fuco809 at gmail dot com | Date: | Tue, 01 Sep 2020 10:59:15 +0000 |
| Subject: | Req #53263 [Com]: Allow realpath cache to function even with open_basedir enabled | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-228833@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=53263&edit=1
ID: 53263
Comment by: fuco809 at gmail dot com
Reported by: tomsommer@php.net
Summary: Allow realpath cache to function even with
open_basedir enabled
Status: Wont fix
Type: Feature/Change Request
Package: Safe Mode/open_basedir
Operating System: *
PHP Version: 5.3.3
Block user comment: N
Private report: N
New Comment:
https://github.com/Whissi/realpath_turbo
why such a soltion can not be integrated as option in php core?
Previous Comments:
------------------------------------------------------------------------
[2019-11-14 15:42:44] retertertert at fgfgfg dot com
and if you don't want to implement that check give sensile people which know their environment
a ini-option instead disable the realpath cache *hardcoded* based on another ini-option with no
chance to say "dear php runtime: look i disabled the race-condition with symlinks and hence the
cache is fine, use it"
or fix symlink() to now allow "then redirect that symlink to a path outside it" which
would close the issue where it happens instead work around it
------------------------------------------------------------------------
[2019-11-14 15:38:08] retertertert at fgfgfg dot com
> One script could, during its lifetime, create and
> resolve a symlink to a path within open_basedir,
> then redirect that symlink to a path outside it
i wonder how it will do that with disable_functions="symlink" which is global and known at
startup and with all exec&freinds also in disbale_functions
------------------------------------------------------------------------
[2019-11-14 15:34:16] requinix@php.net
@michael: It applies to one request as well as it does multiple requests. One script could, during
its lifetime, create and resolve a symlink to a path within open_basedir, then redirect that symlink
to a path outside it.
In the interests of having one fewer open tickets regarding open_basedir performance, and since
#52312 is still open, I'm going to wontfix this per @rasmus's comment.
------------------------------------------------------------------------
[2019-11-14 11:38:57] michael dot vorisek at email dot cz
Is the cache issue related only when the PHP process is resused for multiple requests with different
open_basedir values?
If yes, an extra switch makes 100% sense. The security is 100% kept and realpath cache will be
available which makes up too 10x the performace on Windows with file heavy scripts.
------------------------------------------------------------------------
[2010-11-08 17:44:30] rasmus@php.net
I don't think the security problem is fixable. We have no way to prevent the contents behind a
cache entry from changing which is the root of the security problem. And I don't see the point
in open_basedir if you remove the security aspect. The less secure toggle is to simply turn off
open_basedir. An open_basedir feature that doesn't actually guarantee that users can't
open files outside of the specified base directory isn't useful.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=53263
--
Edit this bug report at https://bugs.php.net/bug.php?id=53263&edit=1