Re: PHP6, drop open_basedir?
| From: | Johannes Schlüter | Date: | Tue, 17 Jun 2014 10:32:45 +0000 |
| Subject: | Re: PHP6, drop open_basedir? | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-74939@lists.php.net to get a copy of this message | ||
On Tue, 2014-06-17 at 10:26 +0200, Pierre Joye wrote:
> I think it is not worth the effort to keep maintaining something that
> will never be as safe as system level permissions.
>
> What do you think about removing it in php 6? Thoughts?
I don't see big maintenance issues. Most stream operations use PHP
streams which encapsulate that. Now there are 25 extensions directly
referring to open_basedir. From a quick look it seems that in all of
those cases we'd have to replace the open_basedir check by resolving
using VCWD (which open_basedir checks do implicitly[1]) which is
required by TSRM, thus we wouldn't win anything there.
Secondly, yes, this is not secure and not safe (and luckily not called
safe_basedir) but it is a mitigation against easy exploitation of
programming bugs and as such serves a purpose even when not protecting
against truly malicious people, especially ones with script execution
privileges.
johannes
[1] In some cases there might be bugs due to missing extra VCWD which i
didn't check now might be worth checking by somebody interested in TSRM