Bug #80113 [Opn->Csd]: .user.ini may not be applied in subdirectories if CONTEXT_DOCUMENT_ROOT is set

From: Date: Mon, 19 Oct 2020 09:25:47 +0000
Subject: Bug #80113 [Opn->Csd]: .user.ini may not be applied in subdirectories if CONTEXT_DOCUMENT_ROOT is set
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229734@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80113&edit=1 ID: 80113 Updated by: nikic@php.net Reported by: mattr at wordfence dot com Summary: .user.ini may not be applied in subdirectories if CONTEXT_DOCUMENT_ROOT is set -Status: Open +Status: Closed Type: Bug Package: CGI/CLI related Operating System: Linux PHP Version: 8.0.0beta3 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: I've reverted the CONTEXT_DOCUMENT_ROOT change for now, so this should be fixed. Previous Comments: ------------------------------------------------------------------------ [2020-09-22 14:57:33] mattr at wordfence dot com I'm actually not trying to use CONTEXT_DOCUMENT_ROOT for anything. Apache sets it when using this kind of CGI configuration, and after the change in 64865, PHP tries to use that to find .user.ini instead of the DOCUMENT_ROOT, which would be the correct path in this case. ------------------------------------------------------------------------ [2020-09-22 14:49:35] willypbender83 at gmail dot com This was introduced as a fix for https://bugs.php.net/bug.php?id=64865 What are you using CONTEXT_DOCUMENT_ROOT for? Not for UserDir module? ------------------------------------------------------------------------ [2020-09-16 21:09:01] mattr at wordfence dot com Description: ------------ The .user.ini file is no longer applied in subdirectories, when Apache is configured to serve PHP via CGI with configuration like this: ScriptAlias /local-bin /usr/local/bin AddHandler application/x-httpd-php-8-0 .php Action application/x-httpd-php-8-0 /local-bin/php-cgi As far as I can tell, this is caused by the new handling of CONTEXT_DOCUMENT_ROOT in sapi_cgi_activate() in sapi/cgi/cgi_main.c. Using phpinfo, I see that CONTEXT_DOCUMENT_ROOT is not where the php files are located: CONTEXT_DOCUMENT_ROOT: /usr/local/bin DOCUMENT_ROOT: /home/user/public_html When php_cgi_ini_activate_user_config() checks if the script is inside the document root, it is using the value from CONTEXT_DOCUMENT_ROOT, which doesn't match -- so it is no longer looking in parent directories for .user.ini files. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80113&edit=1

« previous php.bugs (#229734) next »