Doc #52460 [NEW]: undocumented upload_tmp_dir fallback vs. open_basedir

From: Date: Tue, 27 Jul 2010 16:49:04 +0000
Subject: Doc #52460 [NEW]: undocumented upload_tmp_dir fallback vs. open_basedir
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-4753@lists.php.net to get a copy of this message
From: Operating system: Debian Lenny PHP version: 5.3.3 Package: Filesystem function related Bug Type: Documentation Problem Bug description:undocumented upload_tmp_dir fallback vs. open_basedir Description: ------------ When upload_tmp_dir is not writable by the user PHP runs as, PHP falls back to the system default (eg. /tmp/). This is not stated in the documentation which reads "If not *specified* PHP will use the system's default." Sample config: upload_tmp_dir /var/www/tmp/ open_basedir /var/www/ Uploading a file with /var/www/tmp not writable by PHP, PHP gives an erroneous warning message that points to open_basedir problems with /tmp/ rather than the actual upload_tmp_dir. A very similar problem was reported in http://bugs.php.net/bug.php?id=44562 but rejected. Originally found in 5.2.6-1+lenny8 and confirmed in 5.3.3. Test script: --------------- <html> <head><title>Upload Bug test</title></head> <body> <form method="post" action="<?php echo $_SERVER['PHP_SELF']; ?>" enctype="multipart/form-data"> <input type="file" name="userfile" /> <input type="submit" value="go" /> </form> <?php if (isset($_FILES['userfile'])) { if (!is_uploaded_file($_FILES['userfile']['tmp_name']) || !is_file($_FILES['userfile']['tmp_name'])) { echo "upload_problem with {$_FILES["userfile"]["tmp_name"]}<br />\n"; echo "upload_tmp_dir is " . ini_get("upload_tmp_dir") . "<br />\n"; } echo "done"; } ?> </body> </html> Expected result: ---------------- PHP Warning: File upload error - unable to create a temporary file in /var/www/tmp in Unknown on line 0 Actual result: -------------- PHP Warning: Unknown: open_basedir restriction in effect. File(/tmp) is not within the allowed path(s): (/var/www/) in Unknown on line 0 PHP Warning: File upload error - unable to create a temporary file in Unknown on line 0 -- Edit bug report at http://bugs.php.net/bug.php?id=52460&edit=1 -- Try a snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=52460&r=trysnapshot52 Try a snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=52460&r=trysnapshot53 Try a snapshot (trunk): http://bugs.php.net/fix.php?id=52460&r=trysnapshottrunk Fixed in SVN: http://bugs.php.net/fix.php?id=52460&r=fixed Fixed in SVN and need be documented: http://bugs.php.net/fix.php?id=52460&r=needdocs Fixed in release: http://bugs.php.net/fix.php?id=52460&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=52460&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=52460&r=needscript Try newer version: http://bugs.php.net/fix.php?id=52460&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=52460&r=support Expected behavior: http://bugs.php.net/fix.php?id=52460&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=52460&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=52460&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=52460&r=globals PHP 4 support discontinued: http://bugs.php.net/fix.php?id=52460&r=php4 Daylight Savings: http://bugs.php.net/fix.php?id=52460&r=dst IIS Stability: http://bugs.php.net/fix.php?id=52460&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=52460&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=52460&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=52460&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=52460&r=mysqlcfg

« previous php.doc.bugs (#4753) next »