Bug #69240 [Fbk->NoF]: is_dir() warns of open_basedir restriction on non-existent directory in config

From: Date: Sun, 30 May 2021 04:22:07 +0000
Subject: Bug #69240 [Fbk->NoF]: is_dir() warns of open_basedir restriction on non-existent directory in config
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234094@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69240&edit=1

 ID:             69240
 Updated by:     php-bugs@lists.php.net
 Reported by:    andrea dot cristaudo at gmail dot com
 Summary:        is_dir() warns of open_basedir restriction on
                 non-existent directory in config
-Status:         Feedback
+Status:         No Feedback
 Type:           Bug
 Package:        Safe Mode/open_basedir
 PHP Version:    5.5.22
 Assigned To:    cmb
 Private report: N

 New Comment:

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.


Previous Comments:
------------------------------------------------------------------------
[2021-05-20 13:23:31] cmb@php.net

Why would you want to specify a non existent directory as
open_basedir in the first place?

------------------------------------------------------------------------
[2016-08-06 16:02:19] ben at indietorrent dot org

A follow-up to my previous comment.

I'm not sure if or when the exact message was changed, but having encountered this more
recently (in PHP 7), the \ErrorException message is in fact correct in that it notes (too subtly, in
my opinion) that the *File* is not within the allowed paths.

Maybe I had simply overlooked this most important distinction in the error message: the message is
referring to a *file*, not a *directory*.

Let's look at a clearer example of this problem. This is triggered in Symfony:

----
ErrorException in ExecutableFinder.php line 63:
is_executable(): open_basedir restriction in effect. File(/usr/share/php) is not within the allowed
path(s):
(/usr/share/php:/tmp:/usr/share/phpmyadmin:/etc/phpmyadmin:/var/lib/phpmyadmin:/usr/local/zend/var/zray/extensions:/usr/local/zend/share:/usr/local/zend/var/plugins)

is_dir(): open_basedir restriction in effect. File(/srv/www/example.com/web) is not within the
allowed path(s): (/srv/www/example.com/web)
----

What is actually happening here is that Symfony is poking-around for PHP executable locations and
calls is_executable(/usr/share/php).

The reason for which the message is so confusing (in my opinion) is that the file for which Symfony
is looking, /usr/share/php, actually points to a *directory* on many systems, such as
Debian/Ubuntu GNU/Linux. Until I studied the message more carefully, I thought, "This is so
strange... the very directory for which PHP is looking is the first one listed in the open_basedir
directive!"

I suppose the important question is whether or not the \ErrorException message changes when I call
is_dir('/usr/share/php') or scandir('/usr/share/php'). I will test this soon.

If not, then the message is ambiguous, and the underlying logic should really be reworked to make
clear whether PHP is attempting to access a file or a directory. One might argue that there is no
meaningful distinction between a file and a directory where the underlying mechanisms are concerned,
but if that is true, the message is then invalid.

------------------------------------------------------------------------
[2015-10-09 15:45:13] ben at indietorrent dot org

I should note also that the \ErrorException's error message is invalid, too, in that the
message is illogical and contradictory.

Here is an example:

is_dir(): open_basedir restriction in effect. File(/srv/www/example.com/web) is not within the
allowed path(s): (/srv/www/example.com/web)

My point is that the referenced file (which is in fact a directory, but that's beside the
point) is indeed present in the allow path(s) list.

It bears mention that this contradictory message seems to be a product of this bug. In other words,
the contradictory message occurs only when the directory in question does not exist on the
filesystem.

------------------------------------------------------------------------
[2015-05-19 11:03:13] cmb@php.net

Related to bug #52065.

------------------------------------------------------------------------
[2015-03-16 07:53:06] fa@php.net

Verified on 5.5.24-dev

Output on 5.6.4 is
bool(true)
bool(fals)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69240


--
Edit this bug report at https://bugs.php.net/bug.php?id=69240&edit=1


Thread (7 messages)

« previous php.bugs (#234094) next »