Bug #80113 [Opn->Csd]: .user.ini may not be applied in subdirectories if CONTEXT_DOCUMENT_ROOT is set
| From: | nikic@php.net | Date: | Mon, 19 Oct 2020 09:25:47 +0000 |
| Subject: | Bug #80113 [Opn->Csd]: .user.ini may not be applied in subdirectories if CONTEXT_DOCUMENT_ROOT is set | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229734@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80113&edit=1
ID: 80113
Updated by: nikic@php.net
Reported by: mattr at wordfence dot com
Summary: .user.ini may not be applied in subdirectories if
CONTEXT_DOCUMENT_ROOT is set
-Status: Open
+Status: Closed
Type: Bug
Package: CGI/CLI related
Operating System: Linux
PHP Version: 8.0.0beta3
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
I've reverted the CONTEXT_DOCUMENT_ROOT change for now, so this should be fixed.
Previous Comments:
------------------------------------------------------------------------
[2020-09-22 14:57:33] mattr at wordfence dot com
I'm actually not trying to use CONTEXT_DOCUMENT_ROOT for anything. Apache sets it when using
this kind of CGI configuration, and after the change in 64865, PHP tries to use that to find
.user.ini instead of the DOCUMENT_ROOT, which would be the correct path in this case.
------------------------------------------------------------------------
[2020-09-22 14:49:35] willypbender83 at gmail dot com
This was introduced as a fix for https://bugs.php.net/bug.php?id=64865
What are you using CONTEXT_DOCUMENT_ROOT for? Not for UserDir module?
------------------------------------------------------------------------
[2020-09-16 21:09:01] mattr at wordfence dot com
Description:
------------
The .user.ini file is no longer applied in subdirectories, when Apache is configured to serve PHP
via CGI with configuration like this:
ScriptAlias /local-bin /usr/local/bin
AddHandler application/x-httpd-php-8-0 .php
Action application/x-httpd-php-8-0 /local-bin/php-cgi
As far as I can tell, this is caused by the new handling of CONTEXT_DOCUMENT_ROOT in
sapi_cgi_activate() in sapi/cgi/cgi_main.c.
Using phpinfo, I see that CONTEXT_DOCUMENT_ROOT is not where the php files are located:
CONTEXT_DOCUMENT_ROOT: /usr/local/bin
DOCUMENT_ROOT: /home/user/public_html
When php_cgi_ini_activate_user_config() checks if the script is inside the document root, it is
using the value from CONTEXT_DOCUMENT_ROOT, which doesn't match -- so it is no longer looking
in parent directories for .user.ini files.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80113&edit=1