[php-src] Issue #9310: OpenSSL stream cert paths do not respect open_basedir restriction
| From: | bukka | Date: | Fri, 12 Aug 2022 09:56:23 +0000 |
| Subject: | [php-src] Issue #9310: OpenSSL stream cert paths do not respect open_basedir restriction | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-242193@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/9310
Author: bukka
### Description
Currently
local_cert and local_pk in stream context are not checked if
they are under open_basedir restriction. This should be probably fixed just in master as it is not
usually a big issue considering that those certs / keys are basically read only and some flow might
have relied on them being in the system path so we don't want to break them in patch release.
However we should still confirm with the open_basedir rules and prohibit it in master branch.
The following code:
```php
<?php
// cert path (existing cert)
$local_cert= "$file_path/cert/local.pem";
ini_set('open_basedir', "$file_path/cert");
$serverCtx = stream_context_create(['ssl' => [
'local_cert' => $local_cert
]]);
var_dump($serverCert);
```
Resulted in this output:
```
resource ...
```
But I expected this output instead:
```
possibly warning
bool(false)
```
### PHP Version
Any
### Operating System
Any