php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Request #55271 open_basedir_include_dir
Submitted: 2011-07-23 09:04 UTC Modified: -
Votes:1
Avg. Score:5.0 ± 0.0
Reproduced:1 of 1 (100.0%)
Same Version:0 (0.0%)
Same OS:0 (0.0%)
From: spamik at yum dot pl Assigned:
Status: Open Package: Safe Mode/open_basedir
PHP Version: 5.3.6 OS:
Private report: No CVE-ID:
Have you experienced this issue?
Rate the importance of this bug to you:

 [2011-07-23 09:04 UTC] spamik at yum dot pl
Description:
------------
I'd like to propose making new php.ini var - open_basedir_include_dir - like 
safe_mode_include_dir , which would allow accessing one dir (files only in it) 
when open_basedir is set to other dir. Usual aplication of this would be "/tmp".

Since 5.3.x php allows tightening open_basedir. However tempnam() function 
(http://www.php.net/manual/pl/function.tempnam.php) does require as first 
parameter dir name. It does not take it from any php.ini var. So programmers had 
to hardcode in almost every program something like tempnam("/tmp",.... 
This makes open_basedir tightening useless as /tmp will remain unaccessible so 
tempnam() will fails. Solution would be open_basedir_include_dir ...



Patches

Add a Patch

Pull Requests

Add a Pull Request

 
PHP Copyright © 2001-2014 The PHP Group
All rights reserved.
Last updated: Sat Apr 19 04:01:55 2014 UTC