#22001 [WFx->Opn]: /php.ini is read instead of configured /usr/local/etc/php.ini !!!
| From: | john@php.net | Date: | Mon, 07 Apr 2003 07:56:37 +0000 |
| Subject: | #22001 [WFx->Opn]: /php.ini is read instead of configured /usr/local/etc/php.ini !!! | ||
| References: | 1 | Groups: | php.doc |
| Request: | Send a blank email to phpdoc+get-969352483@lists.php.net to get a copy of this message | ||
ID: 22001
Updated by: john@php.net
Reported By: mdff at a1 dot net
-Status: Wont fix
+Status: Open
-Bug Type: *Configuration Issues
+Bug Type: Documentation problem
Operating System: Solaris 8
PHP Version: 4.3.0
New Comment:
This behavior should really be documented... Why someone would stick
the php.ini file in root is beyond me, but it should be at least noted.
Previous Comments:
------------------------------------------------------------------------
[2003-04-07 02:51:56] joseluis dot perez at arrakis dot es
OS: Linux Debian 3.0, kernel 2.4.18.
I can´t understand why you don´t plan to fix this 'feature'. It´s an
important security risk.
Ok, let´s try to explain my plataform. I have an Apache that serves
many virtualHosts. I use suexec to control that cgi´s are run in the
jail where all virtualhost are. Each virtualhost has a different uid ,
and CGI´s are run with it´s own uid. This way I can restrict my
customer´s security and privacy. And that´s why it´s so important that
PHP is run as CGI.
I have compiled PHP with '--with-config-file-path=/etc' option. It
worked correctly in the jail and I have a correct php.ini in '/etc'. In
fact, PHP first look './php.ini' and then if it doesn´t exists, it
reads /etc/php.ini. ( I used strace to see it ). I need PHP to run as a
CGI, because I use it in Apache and I need it to generate HTML code, so
I can´t compile it to work as CLI.
I know that when you use -c option you can tell PHP where to look for
php.ini, but when you run PHP in CGI mode, it overrides command line
options. It´s a security matter. I use PHPRC to tell PHP where to look
for php.ini for each of my virtualhosts, but when exists a php.ini file
in the directory where the scripts resides PHP read it and ignore
PHPRC, -c or compilation options.
Feel free to ask any further information you need, and of course
thanks in avdvance.
------------------------------------------------------------------------
[2003-02-02 06:46:50] philip@php.net
Added a link to this bug report in the related existing bug of #21783
so this information will be added to the manual sometime.
http://bugs.php.net/bug.php?id=21783
------------------------------------------------------------------------
[2003-02-02 05:50:38] mdff at a1 dot net
yes... i understand how this is done... now.
but: i did not find anything 'bout this behaviour in the manual...
maybe i overread it, but it should be placed to be seen at 1st (bold,
underline ;-)) maybe in:
http://www.php.net/manual/en/configuration.php#configuration.file
thx, md.
------------------------------------------------------------------------
[2003-02-01 19:42:39] edink@php.net
This is a known issue. PHP searches for php.ini in current working
directory first (exception to this is CLI SAPI) and apache does cd / at
startup so /php.ini gets read.
There are nó current plans to change this.
------------------------------------------------------------------------
[2003-02-01 17:09:10] msopacua@php.net
Please try using this CVS snapshot:
http://snaps.php.net/php4-STABLE-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php4-win32-STABLE-latest.zip
Could you also stop and start apache instead of restart?
I can't reproduce this with current HEAD.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/22001
--
Edit this bug report at http://bugs.php.net/?id=22001&edit=1