Bug #43419 [Opn->Nab]: Using gzfile() with URL and open_basedir

From: Date: Thu, 20 May 2021 16:35:37 +0000
Subject: Bug #43419 [Opn->Nab]: Using gzfile() with URL and open_basedir
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233924@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=43419&edit=1 ID: 43419 Updated by: cmb@php.net Reported by: vinni10 at gmx dot net Summary: Using gzfile() with URL and open_basedir -Status: Open +Status: Not a bug Type: Bug Package: Safe Mode/open_basedir Operating System: Linux (Debian) PHP Version: 5.2.6 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: > [function.gzfile]: could not make seekable That's the relevant error message. In order to make the HTTP wrapper seekable, the stream is copied to the temporary directory. If this cannot be written to for whatever reason (in this case due to open_basedir restriction), the operation fails. This is, however, not a bug. Add the tmp directory to open_basedir, or don't use functionality which may require the tmp directory. Previous Comments: ------------------------------------------------------------------------ [2020-12-21 15:01:19] sji at sj-i dot dev Cannot reproduce this on PHP 7.4 ------------------------------------------------------------------------ [2007-11-27 12:58:01] jani@php.net This is more general issue, anything trying to use /tmp causes this. (there are other reports about this too) ------------------------------------------------------------------------ [2007-11-26 20:36:11] vinni10 at gmx dot net Description: ------------ When you try to read an external file with gzfile() and open_basedir restriction you will get an warning that /tmp is not in allowed paths. Reproduce code: --------------- <?php $url = "http://url/test.gz"; /** Try to use gzfile() with HTTP and open_basedir **/ $var1 = gzfile($url); /** Try to use gzfile() with downloaded file and open_basedir **/ $filename = "dwltest.gz"; file_put_contents($filename, file_get_contents($url)); $var2 = gzfile($filename); unlink($filename); echo "<pre>"; echo "<b>remote gzfile:</b>\n"; var_dump($var1); echo "\n\n<b>local gzfile:</b>\n"; var_dump($var2); echo "</pre>"; ?> Expected result: ---------------- remote gzfile: array(1) { [0]=> string(23) "This is a simple test!" } local gzfile: array(1) { [0]=> string(23) "This is a simple test!" } Actual result: -------------- Warning: gzfile() [function.gzfile]: open_basedir restriction in effect. File(/tmp) is not within the allowed path(s): (/var/www/) in /var/www/gzfile_test.php on line 8 Warning: gzfile(http://url/test.gz) [function.gzfile]: could not make seekable - http://url/test.gz in /var/www/gzfile_test.php on line 8 remote gzfile: bool(false) local gzfile: array(1) { [0]=> string(23) "This is a simple test!" } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=43419&edit=1

« previous php.bugs (#233924) next »