Re: PHP6, drop open_basedir?
| From: | Rasmus Lerdorf | Date: | Wed, 18 Jun 2014 03:49:47 +0000 |
| Subject: | Re: PHP6, drop open_basedir? | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-74965@lists.php.net to get a copy of this message | ||
On 06/17/2014 10:26 AM, Pierre Joye wrote:
> hi,
>
> One of the last reminding so called "security" feature is open_basedir.
>
> On Windows f.e. it is very easy to create application pool with the
> right users/permissions settings (IIS) or only permissions settings
> (Apache). It is not possible to create one user per host on Apache
> using mod_php but I think it is acceptable as it is mostly used as
> development server or dedicated apps.
>
> On linux, fcgi/fpm with linux permissions systems allow pretty much
> the same. And my solutions exist for a per user/application isolation
> system.
>
> I think it is not worth the effort to keep maintaining something that
> will never be as safe as system level permissions.
>
> What do you think about removing it in php 6? Thoughts?
I think you have a very narrow view of how this feature is used.
Security and code quality is about layers. This is a useful layer that
helps verify that an application, or even a subset of an application, is
only able to access a given set of directories. If something tries to
access a file outside of the defined scope, we get an error and we know
there is a bug in the code. I, and many companies out there, rely quite
heavily on this feature to catch mistakes. And yes, there are ways of
getting around it at the PHP-level if you deliberately craft your PHP
code to do so, but that doesn't make the feature any less useful to all
the people using it to catch non-deliberate mistakes.
-Rasmus