#22001 [WFx->Opn]: /php.ini is read instead of configured /usr/local/etc/php.ini !!!

From: Date: Mon, 07 Apr 2003 07:56:37 +0000
Subject: #22001 [WFx->Opn]: /php.ini is read instead of configured /usr/local/etc/php.ini !!!
References: 1  Groups: php.doc 
Request: Send a blank email to phpdoc+get-969352483@lists.php.net to get a copy of this message
ID: 22001 Updated by: john@php.net Reported By: mdff at a1 dot net -Status: Wont fix +Status: Open -Bug Type: *Configuration Issues +Bug Type: Documentation problem Operating System: Solaris 8 PHP Version: 4.3.0 New Comment: This behavior should really be documented... Why someone would stick the php.ini file in root is beyond me, but it should be at least noted. Previous Comments: ------------------------------------------------------------------------ [2003-04-07 02:51:56] joseluis dot perez at arrakis dot es OS: Linux Debian 3.0, kernel 2.4.18. I can´t understand why you don´t plan to fix this 'feature'. It´s an important security risk. Ok, let´s try to explain my plataform. I have an Apache that serves many virtualHosts. I use suexec to control that cgi´s are run in the jail where all virtualhost are. Each virtualhost has a different uid , and CGI´s are run with it´s own uid. This way I can restrict my customer´s security and privacy. And that´s why it´s so important that PHP is run as CGI. I have compiled PHP with '--with-config-file-path=/etc' option. It worked correctly in the jail and I have a correct php.ini in '/etc'. In fact, PHP first look './php.ini' and then if it doesn´t exists, it reads /etc/php.ini. ( I used strace to see it ). I need PHP to run as a CGI, because I use it in Apache and I need it to generate HTML code, so I can´t compile it to work as CLI. I know that when you use -c option you can tell PHP where to look for php.ini, but when you run PHP in CGI mode, it overrides command line options. It´s a security matter. I use PHPRC to tell PHP where to look for php.ini for each of my virtualhosts, but when exists a php.ini file in the directory where the scripts resides PHP read it and ignore PHPRC, -c or compilation options. Feel free to ask any further information you need, and of course thanks in avdvance. ------------------------------------------------------------------------ [2003-02-02 06:46:50] philip@php.net Added a link to this bug report in the related existing bug of #21783 so this information will be added to the manual sometime. http://bugs.php.net/bug.php?id=21783 ------------------------------------------------------------------------ [2003-02-02 05:50:38] mdff at a1 dot net yes... i understand how this is done... now. but: i did not find anything 'bout this behaviour in the manual... maybe i overread it, but it should be placed to be seen at 1st (bold, underline ;-)) maybe in: http://www.php.net/manual/en/configuration.php#configuration.file thx, md. ------------------------------------------------------------------------ [2003-02-01 19:42:39] edink@php.net This is a known issue. PHP searches for php.ini in current working directory first (exception to this is CLI SAPI) and apache does cd / at startup so /php.ini gets read. There are nó current plans to change this. ------------------------------------------------------------------------ [2003-02-01 17:09:10] msopacua@php.net Please try using this CVS snapshot: http://snaps.php.net/php4-STABLE-latest.tar.gz For Windows: http://snaps.php.net/win32/php4-win32-STABLE-latest.zip Could you also stop and start apache instead of restart? I can't reproduce this with current HEAD. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/22001 -- Edit this bug report at http://bugs.php.net/?id=22001&edit=1

« previous php.doc (#969352483) next »