Bug->Doc #46925 [Opn]: when open_basedir="." the working directory is set to the executable location

From: Date: Thu, 20 May 2021 16:29:32 +0000
Subject: Bug->Doc #46925 [Opn]: when open_basedir="." the working directory is set to the executable location
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-18772@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=46925&edit=1 ID: 46925 Updated by: cmb@php.net Reported by: eyal at zend dot com Summary: when open_basedir="." the working directory is set to the executable location Status: Open -Type: Bug +Type: Documentation Problem Package: Safe Mode/open_basedir Operating System: Windows * PHP Version: 5.2.8 Block user comment: N Private report: N New Comment: Well, '.' refers to the current working directory, and on startup, that defaults to the location of the php-cgi executable, when run as (F)CGI. If you set open_basedir only at the request level (i.e. from inside a PHP script), '.' works as advertized in the manual. Note that the php executable does not check the given script for open_basedir violations at all. Previous Comments: ------------------------------------------------------------------------ [2021-05-03 12:18:19] cmb@php.net We even document[1]: | The special value . indicates that the working directory of the | script will be used as the base-directory. [1] <https://www.php.net/manual/en/ini.core.php#ini.open-basedir> ------------------------------------------------------------------------ [2021-05-03 12:15:42] cmb@php.net Related To: Bug #77474 ------------------------------------------------------------------------ [2008-12-23 15:00:29] pajoye@php.net Do we really want to support relative path? It may (incidentally) have worked before but I can't think of any sane usage of a relative path for open_basedir. ------------------------------------------------------------------------ [2008-12-22 11:55:29] eyal at zend dot com Description: ------------ NOTE: Tested with FastCGI module on IIS 7. 1. Verify you have info.php in your docroot. 2. Set the directive open_basedir="." 3. Request the script info.php Reproduce code: --------------- <?php phpinfo(): ?> Expected result: ---------------- The phpinfo() output Actual result: -------------- PHP Warning: Unknown: open_basedir restriction in effect. File(C:\inetpub\wwwroot\info.php) is not within the allowed path(s): (.) in Unknown on line 0 To verify the location that is not restricted you can do the following: Add a virtual directory to the default web site with a physical path of the php-fastCGI.exe and put the info.php there as well. Now you can see that when requesting the file from the virtual directory you will receive the phpinfo() output. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=46925&edit=1

« previous php.doc.bugs (#18772) next »