#29856 [Opn->Csd]: open_basedir "/" not working
| From: | vrana@php.net | Date: | Tue, 14 Sep 2004 11:45:40 +0000 |
| Subject: | #29856 [Opn->Csd]: open_basedir "/" not working | ||
| References: | 1 | Groups: | php.doc |
| Request: | Send a blank email to phpdoc+get-969364053@lists.php.net to get a copy of this message | ||
ID: 29856
Updated by: vrana@php.net
Reported By: petrus at activesec dot biz
-Status: Open
+Status: Closed
Bug Type: Documentation problem
Operating System: Solaris 8
PHP Version: 4.3.8
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
"In httpd.conf, open_basedir can be turned off (e.g. for some virtual
hosts) the same way (link to
http://www.php.net/manual/en/configuration.php)
as any other
configuration directive with 'php_admin_value open_basedir none'."
I wonder why "/" doesn't work. Moreover with the aspect it worked
before.
Previous Comments:
------------------------------------------------------------------------
[2004-08-31 08:18:51] derick@php.net
Marking it as a doc problem then.
------------------------------------------------------------------------
[2004-08-30 19:08:47] petrus at activesec dot biz
Finally, after reading some mail from mailing lists and some try and
error, I found that:
open_basedir none
is equal to
open_basedir "/"
and "/" has no effect at all.
Nevertheless in the documentation is no reference to the especial
"none" parameter.
------------------------------------------------------------------------
[2004-08-26 20:15:32] petrus at activesec dot biz
Description:
------------
This bug report is similar to a solved one (bugid=22220), but looks
like the bug appears again in version 4.3.8:
I just upgrade PHP from version 4.3.4 to version 4.3.8. After upgrade
from 4.3.4 to 4.3.8 open_basedir "/" directive stop working (just like
if I comment it out, no effect at all)
The Web server provides hosting for several domains, all of those with
its own homedir:
<VirtualHost *:* >
ServerName www.<servername>.com
ServerAlias <servername>.com
DocumentRoot /domains/<servername>.com/web
php_admin_value open_basedir
/domains/<servername>.com/web:/tmp
php_admin_flag safe_mode Off
php_admin_flag register_globals On
</VirtualHost>
where open_basedir restric PHP to the homedir. Some especial
directories, for example the webmail directory, is there only one, but
it is shared by all the virtualhosts (http://<virtualhost>/webmail/). I
achieve that using (en
httpd.conf):
Alias /webmail "/apache2/htdocs/horde/imp"
<Directory /apache2/htdocs/horde >
php_admin_flag safe_mode off
php_admin_value upload_tmp_dir /tmp
php_admin_value open_basedir "/"
</Directory>
This worked fine until the upgrade. After it, I get a message claiming
that the open_basedir directive is in use, and that
"/apache2/htdocs/horde/imp" is not in (/).
PHP.ini has no open_basedir tag, al are in apache conf. files using
"php_admin_value".
None of the configuretion file were changes durring the upgrade. After
downgrade to 4.3.4 again the problem desapeared.
4.3.8 configure line:
./configure --with-mysql --with-gd --with-apxs2=/apache2/bin/apxs
--with-ldap --sharedstatedir=/tmp --enable-memory-limit=yes
--enable-debug=no --with-zlib --with-kerberos=no
--prefix=/usr/local/chroot/www/usr/local --with-gettext --with-xml
--with-imap=../imap-2002e --without-imap-ssl
--with-openssl=/usr/local/ssl --with-jpeg-dir=/usr/local
--with-config-file-path=/apache2/conf --enable-ftp=shared
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=29856&edit=1