[php-src] Issue #9317: OpenSSL config path does not respect open_basedir restriction
| From: | bukka | Date: | Fri, 12 Aug 2022 14:01:44 +0000 |
| Subject: | [php-src] Issue #9317: OpenSSL config path does not respect open_basedir restriction | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-242200@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/9317
Author: bukka
### Description
Currently the config in options passed to some functions is not checked if it is inside open_basedir
restriction. This should be probably fixed just in master as it is not usually a big issue
considering that the config is basically read only and some user flows might have relied on it being
in the system path so we don't want to break them in a patch release. However we should still
confirm to the
open_basedir rules and prohibit it in master branch. One thing to note
that this should not be applied on the default path as it would be too big break for not a big gain.
The following code:
```php
<?php
// cert path (existing cert)
$config= "$file_path/config/openssl.cnf";
ini_set('open_basedir', "$file_path/config");
$pkey= openssl_pkey_new([
'config' => $config
]);
var_dump($pkey);
```
Resulted in this output:
```
object...
```
But I expected this output instead:
```
possibly warning
bool(false)
```
### PHP Version
Any
### Operating System
Any