Re: PHP6, drop open_basedir?

From: Date: Thu, 19 Jun 2014 22:17:55 +0000
Subject: Re: PHP6, drop open_basedir?
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-75002@lists.php.net to get a copy of this message
-1 Even when you use a dedicated user per vhost, a defense in depth strategy where you additionally restrict the to not access /tmp or /etc seems right.* Note containers/VM are not always available. chroot + bind mounts _would_ be able to provide that restriction, but it is a messy setup, both in folder structure and in polluting the mounts. AppArmor can be an alternative (assuming you have that LSM in your kernel) although you may need some trickery, as (IMHO) you can't having have a profile with different paths depending on the uid (and goog luck on restricting things like the php error log). I think you should provide -for a few of those alternatives- a recipe of "translating" an open_basedir to provide the same restriction. I suspect it will be quite hard to do (without requiring more server features -sometimes an upgrade-), specially when you start facing requisites like "don't allow enumerating the other accounts on this host". * Obviously, this can only work if the user can't exec outside of the php process. PS: I also disagree with the statement «mod_php but I think it is acceptable as it is mostly used as development server», but it may be considered ‘right’ to remove open_basedir even without that premise.

« previous php.internals (#75002) next »