#44801 [Opn->Csd]: Invalid escaping for passthru() in CLI

From: Date: Fri, 07 Nov 2008 09:52:59 +0000
Subject: #44801 [Opn->Csd]: Invalid escaping for passthru() in CLI
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-1408@lists.php.net to get a copy of this message
ID: 44801 Updated by: vrana@php.net Reported By: twm at twmacinta dot com -Status: Open +Status: Closed Bug Type: Documentation problem Operating System: Red Hat Enterprise Linux ES 3 PHP Version: 5.2.5 New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. "If PHP is compiled with --enable-safe-mode then defaults to On, otherwise Off." Executed binaries are not affected by safe_mode, only the parameters passed which is properly documented. Previous Comments: ------------------------------------------------------------------------ [2008-11-05 17:35:26] twm at twmacinta dot com I think jani was referring to this portion of my note from 27 Apr 1:44pm UTC: I'd like to suggest that the manual be annotated to reflect the changing behavior of the safe mode default. Currently, http://www.php.net/manual/en/ini.php says that the default value for "safe_mode" in "php.ini" is 0. There is no mention that the default changes depending on how the binary was compiled. In fact, I had assumed that the default of 0 only applied when safe mode was compiled into the binary since it would be meaningless otherwise. This page on safe mode also indicates that the safe mode features aren't applied to command line scripts. http://www.php.net/manual/en/features.safe-mode.php says "Warning: These PHP restrictions are not valid in executed binaries, of course." That doesn't seem entirely correct given that it was affecting passthru() in the command line scripts referenced in this bug. ------------------------------------------------------------------------ [2008-11-05 17:18:42] vrana@php.net Please explain what exactly should be documented. ------------------------------------------------------------------------ [2008-04-28 12:31:09] jani@php.net Test is fixed, but the docs need to be fixed too. ------------------------------------------------------------------------ [2008-04-27 13:44:14] twm at twmacinta dot com OK, that's the problem. But given that it is the problem, the test script "bug22414.phpt", which is part of "make test", is bound to fail any time safe mode is compiled in. It makes nested calls to the PHP binary with the "-n" option, which apparently causes safe mode to be turned on since it ignores the test script's custom "php.ini" in that case. So in that respect, maybe this is a bug in "bug22414.phpt"? I'd like to suggest that the manual be annotated to reflect the changing behavior of the safe mode default. Currently, http://www.php.net/manual/en/ini.php says that default value for "safe_mode" in "php.ini" is 0. There is no mention that the default changes depending on how the binary was compiled. In fact, I had assumed that the default of 0 only applied when safe mode was compiled into the binary since it would be meaningless otherwise. This page on safe mode also indicates that the safe mode features aren't applied to command line scripts. http://www.php.net/manual/en/features.safe-mode.php says "Warning: These PHP restrictions are not valid in executed binaries, of course." That's doesn't seem entirely correct given that it was affecting passthru() in the command line scripts referenced in this bug. ------------------------------------------------------------------------ [2008-04-25 16:29:04] jani@php.net Using --enable-safe-mode makes the default be "on". (without this configure option it defaults to "off"). And in the manual it is mentioned that: "Warning: With safe mode enabled, the command string is escaped with escapeshellcmd(). Thus, echo y | echo x becomes echo y \| echo x." The question remains: Did you really turn off safe-mode in php.ini and was it really turned off? (check with phpinfo()) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/44801 -- Edit this bug report at http://bugs.php.net/?id=44801&edit=1

« previous php.doc.bugs (#1408) next »