Req #55271 [Opn->Fbk]: open_basedir_include_dir
| From: | cmb@php.net | Date: | Thu, 20 May 2021 15:27:53 +0000 |
| Subject: | Req #55271 [Opn->Fbk]: open_basedir_include_dir | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233921@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55271&edit=1
ID: 55271
Updated by: cmb@php.net
Reported by: spamik at yum dot pl
Summary: open_basedir_include_dir
-Status: Open
+Status: Feedback
Type: Feature/Change Request
Package: Safe Mode/open_basedir
PHP Version: 5.3.6
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Are you aware that openbase_dir can be set to a list of
directories (like PATH)?
Previous Comments:
------------------------------------------------------------------------
[2011-07-23 09:04:08] spamik at yum dot pl
Description:
------------
I'd like to propose making new php.ini var - open_basedir_include_dir - like
safe_mode_include_dir , which would allow accessing one dir (files only in it)
when open_basedir is set to other dir. Usual aplication of this would be "/tmp".
Since 5.3.x php allows tightening open_basedir. However tempnam() function
(http://www.php.net/manual/pl/function.tempnam.php) does require as first
parameter dir name. It does not take it from any php.ini var. So programmers had
to hardcode in almost every program something like tempnam("/tmp",....
This makes open_basedir tightening useless as /tmp will remain unaccessible so
tempnam() will fails. Solution would be open_basedir_include_dir ...
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=55271&edit=1