Skip to content

opcache_invalidate(): Add a warning about untrusted input - #5871

Open
DanielEScherzer wants to merge 1 commit into
php:masterfrom
DanielEScherzer:opcache_invalidate
Open

DanielEScherzer wants to merge 1 commit into
php:masterfrom
DanielEScherzer:opcache_invalidate

Conversation

@DanielEScherzer

Copy link
Copy Markdown
Member

Inputs are not validated for correctness and can escape the cache directory and remove other .bin files, including those that would otherwise be restricted by open_basedir.

Inputs are not validated for correctness and can escape the cache directory and
remove other `.bin` files, including those that would otherwise be restricted
by `open_basedir`.
Comment on lines +31 to +32
<literal>opcache.file_cache_read_only</literal>
is not enabled, a <parameter>filename</parameter> that starts with

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
<literal>opcache.file_cache_read_only</literal>
is not enabled, a <parameter>filename</parameter> that starts with
<literal>opcache.file_cache_read_only</literal>
(available as of PHP 8.5.0; earlier releases have no equivalent
protection) is not enabled, a <parameter>filename</parameter> that starts with

Comment thread reference/opcache/functions/opcache-invalidate.xml
@DanielEScherzer

Copy link
Copy Markdown
Member Author

I'll hold off on this until after #5881 is done

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants