Bug #42560 [Com]: Empty directory argument to tempnam yields open_basedir problems

From: Date: Sun, 20 Dec 2020 21:58:36 +0000
Subject: Bug #42560 [Com]: Empty directory argument to tempnam yields open_basedir problems
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231194@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=42560&edit=1

 ID:                 42560
 Comment by:         sji at sj-i dot dev
 Reported by:        Bjorn dot Wiberg at its dot uu dot se
 Summary:            Empty directory argument to tempnam yields
                     open_basedir problems
 Status:             Open
 Type:               Bug
 Package:            Safe Mode/open_basedir
 Operating System:   IBM AIX 5.3 5300-08-01-0819
 PHP Version:        5.2.9
 Block user comment: N
 Private report:     N

 New Comment:

https://github.com/php/php-src/pull/6526

This PR fixes the problem.


Previous Comments:
------------------------------------------------------------------------
[2010-02-16 12:31:33] jeffersongranatto at mannesoft dot com dot br

...or active "open_basedir_check" in php_open_temporary_fd

------------------------------------------------------------------------
[2010-02-16 03:13:27] jeffersongranatto at mannesoft dot com dot br

I think... this will not cause side effects.

in the file: ext/standard/file.c
in the function: PHP_FUNCTION(tempnam)
remove:
        if (php_check_open_basedir(dir TSRMLS_CC)) {
                RETURN_FALSE;
        }

in the file: main/php_open_temporary_file.c
in the function: PHPAPI int php_open_temporary_fd_ex
include before the comment:
/* Try the directory given as parameter. */
this:
        if (php_check_open_basedir(dir TSRMLS_CC)) {
                return -1;
        }


And remove this:
        !open_basedir_check
It seems it does not work, and now it will be bad.

------------------------------------------------------------------------
[2009-08-26 05:45:13] Bjorn dot Wiberg at its dot uu dot se

(Don't know about 5.2.10; bug #48276 hinders us from installing that one on our systems, so
personally I cannot verify any changes before 5.2.11 but I'm sure you or some of the other
people who have reported this can. The sample code is included with the original submission.)

------------------------------------------------------------------------
[2009-08-26 05:36:04] Bjorn dot Wiberg at its dot uu dot se

I also verified this, the problem is still present in PHP 5.2.9:

Warning: tempnam(): open_basedir restriction in effect. File() is not within the allowed path(s):
(.:/apache/php/lib/php:/opt/freeware/bin:/tmp:/usr/local/bin:/usr/local/etc/Counter/data:/apache/htdocs/bwiberg)
in /apache/htdocs/bwiberg/test/tempnam.php on line 2 

(and no /tmp/test file present)

------------------------------------------------------------------------
[2009-08-25 19:16:53] rick dot g777 at gmail dot com

Still present in PHP 5.2.9

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=42560


--
Edit this bug report at https://bugs.php.net/bug.php?id=42560&edit=1


Thread (14 messages)

« previous php.bugs (#231194) next »