#44801 [Opn->Csd]: Invalid escaping for passthru() in CLI
| From: | vrana@php.net | Date: | Fri, 07 Nov 2008 09:52:59 +0000 |
| Subject: | #44801 [Opn->Csd]: Invalid escaping for passthru() in CLI | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-1408@lists.php.net to get a copy of this message | ||
ID: 44801
Updated by: vrana@php.net
Reported By: twm at twmacinta dot com
-Status: Open
+Status: Closed
Bug Type: Documentation problem
Operating System: Red Hat Enterprise Linux ES 3
PHP Version: 5.2.5
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
"If PHP is compiled with --enable-safe-mode then defaults to On,
otherwise Off."
Executed binaries are not affected by safe_mode, only the parameters
passed which is properly documented.
Previous Comments:
------------------------------------------------------------------------
[2008-11-05 17:35:26] twm at twmacinta dot com
I think jani was referring to this portion of my note from 27 Apr
1:44pm UTC:
I'd like to suggest that the manual be annotated to reflect the
changing behavior of the safe mode default. Currently,
http://www.php.net/manual/en/ini.php says that
the default value for
"safe_mode" in "php.ini" is 0. There is no mention that the default
changes depending on how the binary was compiled. In fact, I had
assumed that the default of 0 only applied when safe mode was compiled
into the binary since it would be meaningless otherwise.
This page on safe mode also indicates that the safe mode features
aren't applied to command line scripts.
http://www.php.net/manual/en/features.safe-mode.php
says "Warning: These
PHP restrictions are not valid in executed binaries, of course." That
doesn't seem entirely correct given that it was affecting passthru() in
the command line scripts referenced in this bug.
------------------------------------------------------------------------
[2008-11-05 17:18:42] vrana@php.net
Please explain what exactly should be documented.
------------------------------------------------------------------------
[2008-04-28 12:31:09] jani@php.net
Test is fixed, but the docs need to be fixed too.
------------------------------------------------------------------------
[2008-04-27 13:44:14] twm at twmacinta dot com
OK, that's the problem. But given that it is the problem, the test
script "bug22414.phpt", which is part of "make test", is bound to fail
any time safe mode is compiled in. It makes nested calls to the PHP
binary with the "-n" option, which apparently causes safe mode to be
turned on since it ignores the test script's custom "php.ini" in that
case. So in that respect, maybe this is a bug in "bug22414.phpt"?
I'd like to suggest that the manual be annotated to reflect the
changing behavior of the safe mode default. Currently,
http://www.php.net/manual/en/ini.php says that
default value for
"safe_mode" in "php.ini" is 0. There is no mention that the default
changes depending on how the binary was compiled. In fact, I had
assumed that the default of 0 only applied when safe mode was compiled
into the binary since it would be meaningless otherwise.
This page on safe mode also indicates that the safe mode features
aren't applied to command line scripts.
http://www.php.net/manual/en/features.safe-mode.php
says "Warning: These
PHP restrictions are not valid in executed binaries, of course." That's
doesn't seem entirely correct given that it was affecting passthru() in
the command line scripts referenced in this bug.
------------------------------------------------------------------------
[2008-04-25 16:29:04] jani@php.net
Using --enable-safe-mode makes the default be "on". (without this
configure option it defaults to "off").
And in the manual it is mentioned that: "Warning:
With safe mode enabled, the command string is escaped with
escapeshellcmd(). Thus, echo y | echo x becomes echo y \| echo x."
The question remains: Did you really turn off safe-mode in php.ini and
was it really turned off? (check with phpinfo())
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/44801
--
Edit this bug report at http://bugs.php.net/?id=44801&edit=1