Doc #52460 [Opn->Csd]: undocumented upload_tmp_dir fallback vs. open_basedir
| From: | kalle@php.net | Date: | Sat, 23 Oct 2010 07:56:22 +0000 |
| Subject: | Doc #52460 [Opn->Csd]: undocumented upload_tmp_dir fallback vs. open_basedir | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-5348@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=52460&edit=1
ID: 52460
Updated by: kalle@php.net
Reported by: ys at tm-company dot de
Summary: undocumented upload_tmp_dir fallback vs.
open_basedir
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
Operating System: Debian Lenny
PHP Version: 5.3.3
-Assigned To:
+Assigned To: kalle
Block user comment: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
Previous Comments:
------------------------------------------------------------------------
[2010-10-23 09:56:14] kalle@php.net
Automatic comment from SVN on behalf of kalle
Revision: http://svn.php.net/viewvc/?view=revision&revision=304644
Log: Fixed bug #52460 (undocumented upload_tmp_dir fallback vs.
open_basedir)
------------------------------------------------------------------------
[2010-07-27 18:49:03] ys at tm-company dot de
Description:
------------
When upload_tmp_dir is not writable by the user PHP runs as, PHP falls
back to the system default (eg. /tmp/). This is not stated in the
documentation which reads "If not *specified* PHP will use the system's
default."
Sample config:
upload_tmp_dir /var/www/tmp/
open_basedir /var/www/
Uploading a file with /var/www/tmp not writable by PHP, PHP gives an
erroneous warning message that points to open_basedir problems with
/tmp/ rather than the actual upload_tmp_dir.
A very similar problem was reported in
http://bugs.php.net/bug.php?id=44562 but
rejected.
Originally found in 5.2.6-1+lenny8 and confirmed in 5.3.3.
Test script:
---------------
<html>
<head><title>Upload Bug test</title></head>
<body>
<form method="post" action="<?php echo $_SERVER['PHP_SELF'];
?>"
enctype="multipart/form-data">
<input type="file" name="userfile" /> <input
type="submit"
value="go" />
</form>
<?php
if (isset($_FILES['userfile'])) {
if (!is_uploaded_file($_FILES['userfile']['tmp_name']) ||
!is_file($_FILES['userfile']['tmp_name'])) {
echo "upload_problem with {$_FILES["userfile"]["tmp_name"]}<br
/>\n";
echo "upload_tmp_dir is " . ini_get("upload_tmp_dir") . "<br
/>\n";
}
echo "done";
}
?>
</body>
</html>
Expected result:
----------------
PHP Warning: File upload error - unable to create a temporary file in
/var/www/tmp in Unknown on line 0
Actual result:
--------------
PHP Warning: Unknown: open_basedir restriction in effect. File(/tmp) is
not within the allowed path(s): (/var/www/) in Unknown on line 0
PHP Warning: File upload error - unable to create a temporary file in
Unknown on line 0
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=52460&edit=1