Bug #80113 [Com]: .user.ini may not be applied in subdirectories if CONTEXT_DOCUMENT_ROOT is set
| From: | mattr at wordfence dot com | Date: | Tue, 22 Sep 2020 14:57:33 +0000 |
| Subject: | Bug #80113 [Com]: .user.ini may not be applied in subdirectories if CONTEXT_DOCUMENT_ROOT is set | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229141@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80113&edit=1
ID: 80113
Comment by: mattr at wordfence dot com
Reported by: mattr at wordfence dot com
Summary: .user.ini may not be applied in subdirectories if
CONTEXT_DOCUMENT_ROOT is set
Status: Open
Type: Bug
Package: CGI/CLI related
Operating System: Linux
PHP Version: 8.0.0beta3
Block user comment: N
Private report: N
New Comment:
I'm actually not trying to use CONTEXT_DOCUMENT_ROOT for anything. Apache sets it when using
this kind of CGI configuration, and after the change in 64865, PHP tries to use that to find
.user.ini instead of the DOCUMENT_ROOT, which would be the correct path in this case.
Previous Comments:
------------------------------------------------------------------------
[2020-09-22 14:49:35] willypbender83 at gmail dot com
This was introduced as a fix for https://bugs.php.net/bug.php?id=64865
What are you using CONTEXT_DOCUMENT_ROOT for? Not for UserDir module?
------------------------------------------------------------------------
[2020-09-16 21:09:01] mattr at wordfence dot com
Description:
------------
The .user.ini file is no longer applied in subdirectories, when Apache is configured to serve PHP
via CGI with configuration like this:
ScriptAlias /local-bin /usr/local/bin
AddHandler application/x-httpd-php-8-0 .php
Action application/x-httpd-php-8-0 /local-bin/php-cgi
As far as I can tell, this is caused by the new handling of CONTEXT_DOCUMENT_ROOT in
sapi_cgi_activate() in sapi/cgi/cgi_main.c.
Using phpinfo, I see that CONTEXT_DOCUMENT_ROOT is not where the php files are located:
CONTEXT_DOCUMENT_ROOT: /usr/local/bin
DOCUMENT_ROOT: /home/user/public_html
When php_cgi_ini_activate_user_config() checks if the script is inside the document root, it is
using the value from CONTEXT_DOCUMENT_ROOT, which doesn't match -- so it is no longer looking
in parent directories for .user.ini files.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80113&edit=1