Req #54564 [Com]: extension_dir should be used for loading zend_extensions
| From: | giw42161 at uooos dot com | Date: | Wed, 29 Jun 2022 06:19:14 +0000 |
| Subject: | Req #54564 [Com]: extension_dir should be used for loading zend_extensions | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-241831@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=54564&edit=1
ID: 54564
Comment by: giw42161 at uooos dot com
Reported by: tyra3l at gmail dot com
Summary: extension_dir should be used for loading
zend_extensions
Status: Closed
Type: Feature/Change Request
Package: Scripting Engine problem
PHP Version: 5.3.6
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
(https://centurylawfirm.in/)gist.github.com
(https://centurylawfirm.in/blog/divorce-lawyer-in-delhi-2/)gist.github.com
(https://centurylawfirm.in/blog/debt-recovery-tribunal-drt/)gist.github.com
(https://centurylawfirm.in/blog/get-bail-in-india/)gist.github.com
(https://centurylawfirm.in/blog/best-lawyer-for-criminal-case/)gist.github.com
(https://centurylawfirm.in/blog/high-court-cases/)gist.github.com
(https://centurylawfirm.in/blog/cheque-bounce-case/)gist.github.com
(https://centurylawfirm.in/blog/how-to-take-mutual-divorce/)gist.github.com
Previous Comments:
------------------------------------------------------------------------
[2013-11-26 21:54:02] rainer dot jung at kippdata dot de
This has already been fixed in master and 5.5:
http://git.php.net/?p=php-src.git;a=commitdiff;h=0b8b6a727ddd31ff14e4af919c77a3f1b5e2b3f0
http://git.php.net/?p=php-src.git;a=commitdiff;h=0def1ca59a60d9fa3a01900c9c09173fbbb9e8e0
It might make sense to backport to 5.4.
------------------------------------------------------------------------
[2013-11-26 19:10:48] rainer dot jung at kippdata dot de
Clarification: tyrael meant: "extension_dir is *not* honored for zend_extension=".
------------------------------------------------------------------------
[2012-09-16 07:23:17] tyrael@php.net
Stas, I'm not sure I'm following your reasoning here.
extension_dir exists, and it is pretty standard in each and every distribution to
rely on this behavior, so bringing this issue against my proposal means that you
either missed my point (extension_dir is honored for zend_extension= like it does
for extension=) or you somehow think that loading a rouge zend extension has
bigger security implications, which I can't see.
ps: Binary Planting isn't really similar with what we have here, the issue with
that is that it allows loading dll's from the current directory, while we would
only allow loading extensions from the paths listed in extension_dir.
------------------------------------------------------------------------
[2012-09-16 06:54:57] stas@php.net
I think loading extensions through relative path opens a way to all kinds of
dangerous behavior and may have problematic security implications - like ones
described here: http://arstechnica.com/information-technology/2010/08/new-
windows-dll-security-flaw-everything-old-is-new-again/. I'm not sure also why it
is necessary - why can't PHP extension be installed in extension dir and run from
there? If one needs multiple ones, multiple php.ini files can always be used.
------------------------------------------------------------------------
[2011-04-18 23:05:25] tyra3l at gmail dot com
Description:
------------
I've brought this topic on the internals
http://marc.info/?l=php-internals&m=130314285822279&w=2
and I think that it would be useful and more consistent, if this could be changed,
so one could easily load both "normal" and zend extensions without the need to use
absolute paths.
Test script:
---------------
php -n -d zend_extension=xdebug.so -r ''
Actual result:
--------------
Failed loading xdebug.so: xdebug.so: cannot open shared object file: No such file
or directory
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=54564&edit=1