Edit report at https://bugs.php.net/bug.php?id=52312&edit=1
ID: 52312
Comment by: rtrtrtrtrt at dfdfdfdf dot dfd
Reported by: v dot damore at gmail dot com
Summary: PHP safe_mode/open_basedir - lstat performance
problem
Status: Wont fix
Type: Feature/Change Request
Package: Safe Mode/open_basedir
Operating System: Linux
PHP Version: 5.2.13
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
which design?
a stubborn hardcoded "and now we disable it" don't deserve the word
"design" when it could be an ini-option given that on sane hosts symlink() and link() are
disabled and so the security issue don't exist
but unless someone designs the realpath cache in a way that it is useable (shared) to gain anything
it don't matter too much
Previous Comments:
------------------------------------------------------------------------
[2021-05-21 10:57:57] cmb@php.net
Hm, and long and fruitless discussion about a deliberate and
documented design design decision. Obviously, this bug tracker
isn't suitable for this. If anybody is still interested in seeing
this improved, please pursue the RFC process[1].
[1] <https://wiki.php.net/rfc/howto>
------------------------------------------------------------------------
[2019-01-05 16:16:54] spam2 at rhsoft dot net
out-of-tree extensions are always a problem when it comes to minor nd major updates even even the
stuff on pecl.php.net is to avoid whenever possible
"Instead of setting open_basedir you will set realpath_turbo.open_basedir" is a crude hack
which requires you to touch each and every vhost and that all because stubborn decisions for no gain
----------------------------------
[builduser@testserver:/rpmbuild/SOURCES]$ cat php-72-realpath-cache-openbasedir.patch
--- php-7.1.9-original/main/main.c 2017-08-16 18:06:53.000000000 +0200
+++ php-7.1.9-patched/main/main.c 2017-08-17 14:11:05.827653357 +0200
@@ -1646,9 +1646,9 @@
}
/* Disable realpath cache if an open_basedir is set */
- if (PG(open_basedir) && *PG(open_basedir)) {
- CWDG(realpath_cache_size_limit) = 0;
- }
+ /* if (PG(open_basedir) && *PG(open_basedir)) { */
+ /* CWDG(realpath_cache_size_limit) = 0; */
+ /*}*/
if (PG(expose_php)) {
sapi_add_header(SAPI_PHP_VERSION_HEADER, sizeof(SAPI_PHP_VERSION_HEADER)-1,
1);
@@ -2236,9 +2236,9 @@
#endif
/* Disable realpath cache if an open_basedir is set */
- if (PG(open_basedir) && *PG(open_basedir)) {
- CWDG(realpath_cache_size_limit) = 0;
- }
+ /*if (PG(open_basedir) && *PG(open_basedir)) { */
+ /* CWDG(realpath_cache_size_limit) = 0;*/
+ /*}*/
/* initialize stream wrappers registry
* (this uses configuration parameters from php.ini)
----------------------------------
[builduser@testserver:/rpmbuild/SOURCES]$ cat php-73-realpath-cache-openbasedir.patch
--- php-7.3.0-original/main/main.c 2018-07-31 13:33:48.000000000 +0200
+++ php-7.3.0-patched/main/main.c 2018-07-31 14:01:15.144001078 +0200
@@ -1798,9 +1798,9 @@
}
/* Disable realpath cache if an open_basedir is set */
- if (PG(open_basedir) && *PG(open_basedir)) {
- CWDG(realpath_cache_size_limit) = 0;
- }
+ /*if (PG(open_basedir) && *PG(open_basedir)) { */
+ /* CWDG(realpath_cache_size_limit) = 0; */
+ /*}*/
if (PG(expose_php)) {
sapi_add_header(SAPI_PHP_VERSION_HEADER, sizeof(SAPI_PHP_VERSION_HEADER)-1,
1);
@@ -2292,9 +2292,9 @@
#endif
/* Disable realpath cache if an open_basedir is set */
- if (PG(open_basedir) && *PG(open_basedir)) {
- CWDG(realpath_cache_size_limit) = 0;
- }
+ /*if (PG(open_basedir) && *PG(open_basedir)) { */
+ /* CWDG(realpath_cache_size_limit) = 0; */
+ /*}*/
PG(have_called_openlog) = 0;
------------------------------------------------------------------------
[2019-01-05 16:09:13] wbob at buerotiger dot de
as alternative to patching sources (and as it wasn't mentioned yet in this bug#) there's
https://github.com/Whissi/realpath_turbo
------------------------------------------------------------------------
[2019-01-05 15:03:53] spam2 at rhsoft dot net
and that behavior is still plain wrong which won't be changed by any documentation - hell i am
tried of such compile time crazyiness and the need to patch sources
with disable_functions="link,symlink" that security problem don't exist on shared
hosting and on shared hosting where people only have access to a CMS it donÃt exist at all to
begin with hence make it a PIP_INI_SYSTEM option
and without a shared memory the whole cache don't work as expected at all
https://bugs.php.net/bug.php?id=73887
https://bugs.php.net/bug.php?id=73888
------------------------------------------------------------------------
[2019-01-05 13:23:10] wbob at buerotiger dot de
open_basedir disabling the realpath cache is now documented in the related ini.core sections, see https://bugs.php.net/bug.php?id=77406
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=52312
--
Edit this bug report at https://bugs.php.net/bug.php?id=52312&edit=1