Difference between revisions of "PHP"
Unnilennium (talk | contribs) |
|||
Line 1: | Line 1: | ||
+ | Starting SME10 php module is not used anymore for httpd. Instead we rely on php-fpm for every available version of php available. By default we provide the following versions : 54 (base one maintained by Red-Hat), 55, 56, 70, 71, 72, 73, 74, 80. | ||
+ | |||
+ | === Available properties === | ||
+ | First you need to decide if you want to alter the php behaviour for an ibay or for a specific php version, of for all php versions. | ||
+ | {| class="wikitable" | ||
+ | |+db configuration properties | ||
+ | !keys | ||
+ | !role | ||
+ | ! | ||
+ | |- | ||
+ | |php | ||
+ | |customization of /etc/php.ini | ||
+ | |for php54 | ||
+ | |- | ||
+ | |php55 | ||
+ | |customization of /opt/remi/php55/root/etc/php.ini | ||
+ | | rowspan="8" |if no properties defined, will use php keys properties | ||
+ | |- | ||
+ | |php56 | ||
+ | |customization of /opt/remi/php56/root/etc/php.ini | ||
+ | |- | ||
+ | |php70 | ||
+ | |customization of /etc/opt/remi/php70/php.ini | ||
+ | |- | ||
+ | |php71 | ||
+ | |customization of /etc/opt/remi/php71/php.ini | ||
+ | |- | ||
+ | |php72 | ||
+ | |customization of /etc/opt/remi/php72/php.ini | ||
+ | |- | ||
+ | |php73 | ||
+ | |customization of /etc/opt/remi/php73/php.ini | ||
+ | |- | ||
+ | |php74 | ||
+ | |customization of /etc/opt/remi/php74/php.ini | ||
+ | |- | ||
+ | |php80 | ||
+ | |customization of /etc/opt/remi/php80/php.ini | ||
+ | |} | ||
+ | Every version of php has its own php-fpm service running, the related configuration db entry is php-fpm for php (ie php54), php55-php-fpm for php55 and so on. If you reallly want to disable one version of php, you need to do for php55 | ||
+ | config setprop php55-php-fpm status disabled | ||
+ | signal-event webapps-update | ||
+ | |||
+ | <br /> | ||
+ | {| class="wikitable" | ||
+ | |+ | ||
+ | !php setting | ||
+ | !ibay property | ||
+ | !php.ini property | ||
+ | !default | ||
+ | !note | ||
+ | |- | ||
+ | | - | ||
+ | |PHPVersion | ||
+ | | - | ||
+ | |74 | ||
+ | |can vary upon update if left empty | ||
+ | |- | ||
+ | |allow_url_fopen | ||
+ | |AllowUrlfOpen | ||
+ | |AllowUrlFopen | ||
+ | |off | ||
+ | |unsecure keep to off | ||
+ | |- | ||
+ | |allow_url_include | ||
+ | | - | ||
+ | | - | ||
+ | |off | ||
+ | | | ||
+ | |- | ||
+ | |auto_prepend_file | ||
+ | |AutoPrependFile | ||
+ | | - | ||
+ | |enabled | ||
+ | |/usr/share/php/auth_translation.php unless disabled | ||
+ | |- | ||
+ | |disable_functions | ||
+ | |DisabledFunctions | ||
+ | | - | ||
+ | |system,show_source, symlink,exec,dl,shell_exec,passthru,phpinfo,escapeshellarg,escapeshellcmd | ||
+ | | | ||
+ | |- | ||
+ | |display_errors | ||
+ | |DisplayErrors | ||
+ | | - | ||
+ | |off | ||
+ | | | ||
+ | |- | ||
+ | |error_log | ||
+ | | - | ||
+ | | - | ||
+ | |/var/log/php/$key/error.log | ||
+ | | | ||
+ | |- | ||
+ | |error_reporting | ||
+ | |ErrorReporting | ||
+ | | - | ||
+ | |E_ALL & ~E_NOTICE & ~E_DEPRECATED & ~E_STRICT | ||
+ | | | ||
+ | |- | ||
+ | |expose_php | ||
+ | | - | ||
+ | |ExposePHP | ||
+ | |Off | ||
+ | | | ||
+ | |- | ||
+ | |file_upload | ||
+ | |FileUpload | ||
+ | | - | ||
+ | |Off | ||
+ | | | ||
+ | |- | ||
+ | |mail.add_x_header | ||
+ | | - | ||
+ | |MailAddXHeader | ||
+ | |disabled | ||
+ | |only global, not per php version | ||
+ | |- | ||
+ | |mail.force_extra_parameters | ||
+ | |MailForceSender | ||
+ | |MailForceSender | ||
+ | |root@$DomainName | ||
+ | |ibayname@$DomainName for ibays | ||
+ | |- | ||
+ | |mail.log | ||
+ | | - | ||
+ | |MailLog | ||
+ | |disabled | ||
+ | | | ||
+ | |- | ||
+ | |max_execution_time | ||
+ | |MaxExecutionTime | ||
+ | |MaxExecutionTime | ||
+ | |30 | ||
+ | | | ||
+ | |- | ||
+ | |max_file_uploads | ||
+ | | - | ||
+ | |MaxFileUpload | ||
+ | |20 | ||
+ | | | ||
+ | |- | ||
+ | |max_input_time | ||
+ | |MaxInputTime | ||
+ | |MaxInputTime | ||
+ | |60 | ||
+ | | | ||
+ | |- | ||
+ | |memory_limit | ||
+ | |MemoryLimit | ||
+ | |MemoryLimit | ||
+ | |128M | ||
+ | | | ||
+ | |- | ||
+ | |open_basedir | ||
+ | |PHPBaseDir | ||
+ | | - | ||
+ | |/home/e-smith/files/ibays/IBAYNAME/:/var/lib/php/IBAYNAME/:/usr/share/php/:/usr/share/pear/:/opt/remi/php$version/root/usr/share/pear/:/opt/remi/php$version/root/usr/share/php/ | ||
+ | | | ||
+ | |- | ||
+ | |post_max_size | ||
+ | |PostMaxSize | ||
+ | |PostMaxSize | ||
+ | |20M | ||
+ | | | ||
+ | |- | ||
+ | |security.limit_extensions | ||
+ | |AllowPHTML | ||
+ | | | ||
+ | |disabled | ||
+ | |allow php to interprete more file (.php .htm .html .phar .phtml .xml) | ||
+ | |- | ||
+ | |sendmail_from | ||
+ | | - | ||
+ | |MailForceSender | ||
+ | |root@$DomainName | ||
+ | | | ||
+ | |- | ||
+ | |sendmail_path | ||
+ | | - | ||
+ | |SendmailPath | ||
+ | |/usr/sbin/sendmail -t -i | ||
+ | | | ||
+ | |- | ||
+ | |short_open_tag | ||
+ | | - | ||
+ | |ShortOpenTag | ||
+ | |On | ||
+ | | | ||
+ | |- | ||
+ | |upload_max_filesize | ||
+ | |UploadMaxFilesize | ||
+ | |UploadMaxFilesize | ||
+ | |10M | ||
+ | | | ||
+ | |} | ||
+ | if you want to set a specific value for an ibay, here we use php80 for ibay MYIBAY and avoid to have any disabled function: | ||
+ | db accounts setprop MYIBAY disable_functions none PHPVersion 80 | ||
+ | signal-event webapps-update | ||
+ | {{Note box|It is highly suggested to install smeserver-webhosting contrib to set your ibay php values from the server-manager. Everything is available and it prevent you from doing any mistake.}} | ||
+ | |||
===Display Error Messages=== | ===Display Error Messages=== | ||
Line 8: | Line 209: | ||
{{Warning box|It is strongly advised to disable display errors after you have tracked and solved the problem, as the displayed error message might provide information (like filesystem layout) that only should be known to the system administrators and not to users, let alone people with bad intentions.}} | {{Warning box|It is strongly advised to disable display errors after you have tracked and solved the problem, as the displayed error message might provide information (like filesystem layout) that only should be known to the system administrators and not to users, let alone people with bad intentions.}} | ||
− | ====Enable changes==== | + | ====Enable changes for all php versions==== |
If you (for debugging purposes for instance) would like to enable it you can do it with the instructions found below: | If you (for debugging purposes for instance) would like to enable it you can do it with the instructions found below: | ||
Line 44: | Line 245: | ||
/etc/rc7.d/S86httpd-e-smith restart | /etc/rc7.d/S86httpd-e-smith restart | ||
+ | ====Enable changes for a specific ibay==== | ||
+ | Starting SME10 and smeserver-php-3.0.0-39 | ||
+ | db accounts setprop MYIBAY DisplayErrors enabled | ||
+ | signal-event webapps-update | ||
===Open basedir restriction=== | ===Open basedir restriction=== | ||
SME Server has a security measure in place which is called 'open basedir restriction'. This measure prevents PHP from executing or invoking other PHP scripts outside the scope of it's own tree in other words it creates a 'sandbox' or 'jail'. | SME Server has a security measure in place which is called 'open basedir restriction'. This measure prevents PHP from executing or invoking other PHP scripts outside the scope of it's own tree in other words it creates a 'sandbox' or 'jail'. | ||
Line 58: | Line 263: | ||
<ol> | <ol> | ||
(Please also see: [http://wiki.contribs.org/Useful_Commands#PHP_Related_Commands these] instructions on the [http://wiki.contribs.org/Useful_Commands Useful_Commands] page.) | (Please also see: [http://wiki.contribs.org/Useful_Commands#PHP_Related_Commands these] instructions on the [http://wiki.contribs.org/Useful_Commands Useful_Commands] page.) | ||
− | <!--Please do not remove the following closing tag as a fromatting/rendering bug will kick in, for more details see: http://bugzilla.wikimedia.org/show_bug.cgi?id=10893-- | + | <!--Please do not remove the following closing tag as a fromatting/rendering bug will kick in, for more details see: http://bugzilla.wikimedia.org/show_bug.cgi?id=10893--><li>Open a SME Server shell as root user and document the current setting of the PHPBaseDir directive by writing down the output of the following command: |
db accounts getprop ibayname PHPBaseDir | db accounts getprop ibayname PHPBaseDir | ||
Be careful to write it down to the letter as we need it in the next step | Be careful to write it down to the letter as we need it in the next step | ||
Line 65: | Line 270: | ||
</li><li>Decide on what directory you would like to add and issue the following: | </li><li>Decide on what directory you would like to add and issue the following: | ||
db accounts setprop ibayname PHPBaseDir value | db accounts setprop ibayname PHPBaseDir value | ||
− | |||
Replace ibayname with the name of the ibay and value with the old value for the PHPBaseDir directive you have written down and a colon (:) followed by the full path to the directory you would like to add with a tailing slash (/), e.g. | Replace ibayname with the name of the ibay and value with the old value for the PHPBaseDir directive you have written down and a colon (:) followed by the full path to the directory you would like to add with a tailing slash (/), e.g. | ||
db accounts setprop Primary PHPBaseDir /home/e-smith/files/ibays/Primary/html/:/opt/gallery2/ | db accounts setprop Primary PHPBaseDir /home/e-smith/files/ibays/Primary/html/:/opt/gallery2/ | ||
− | |||
Above command would allow for invocation of scripts in the /opt/gallery2 path from the Primary ibay html folder by PHP. | Above command would allow for invocation of scripts in the /opt/gallery2 path from the Primary ibay html folder by PHP. | ||
− | |||
To allow uploading of files to via http to a ibay name wiki | To allow uploading of files to via http to a ibay name wiki | ||
db accounts setprop wiki PHPBaseDir /home/e-smith/files/ibays/wiki/:/tmp/ | db accounts setprop wiki PHPBaseDir /home/e-smith/files/ibays/wiki/:/tmp/ | ||
Line 101: | Line 303: | ||
See also: | See also: | ||
− | * [[bugzilla:1120]] | + | *[[bugzilla:1120]] |
− | * [[bugzilla:2132]] | + | *[[bugzilla:2132]] |
− | * http://forums.contribs.org/index.php?topic=31518 | + | *http://forums.contribs.org/index.php?topic=31518 |
===PHP 5 with php-mcrypt=== | ===PHP 5 with php-mcrypt=== | ||
Line 113: | Line 315: | ||
<ol> | <ol> | ||
− | + | <li>Download php-mcrypt rpms needed | |
− | |||
cd /tmp | cd /tmp | ||
− | + | wget http://rpms.famillecollet.com/enterprise/5/olds/i386/php-common-5.2.10-1.el5.remi.i386.rpm | |
− | + | wget http://rpms.famillecollet.com/enterprise/5/olds/i386/php-mcrypt-5.2.10-1.el5.remi.i386.rpm | |
− | </li><li>Make a backup of your current php.ini file | + | </li><li>Make a backup of your current php.ini file'(because the install will change the file) |
cp /etc/php.ini /etc/php.ini.org | cp /etc/php.ini /etc/php.ini.org | ||
Line 134: | Line 335: | ||
mv /etc/php.ini /etc/php.ini.old | mv /etc/php.ini /etc/php.ini.old | ||
− | + | mv /etc/php.ini.org /etc/php.ini | |
</li><li>Restart all services | </li><li>Restart all services |
Revision as of 05:22, 18 September 2021
Starting SME10 php module is not used anymore for httpd. Instead we rely on php-fpm for every available version of php available. By default we provide the following versions : 54 (base one maintained by Red-Hat), 55, 56, 70, 71, 72, 73, 74, 80.
Available properties
First you need to decide if you want to alter the php behaviour for an ibay or for a specific php version, of for all php versions.
keys | role | |
---|---|---|
php | customization of /etc/php.ini | for php54 |
php55 | customization of /opt/remi/php55/root/etc/php.ini | if no properties defined, will use php keys properties |
php56 | customization of /opt/remi/php56/root/etc/php.ini | |
php70 | customization of /etc/opt/remi/php70/php.ini | |
php71 | customization of /etc/opt/remi/php71/php.ini | |
php72 | customization of /etc/opt/remi/php72/php.ini | |
php73 | customization of /etc/opt/remi/php73/php.ini | |
php74 | customization of /etc/opt/remi/php74/php.ini | |
php80 | customization of /etc/opt/remi/php80/php.ini |
Every version of php has its own php-fpm service running, the related configuration db entry is php-fpm for php (ie php54), php55-php-fpm for php55 and so on. If you reallly want to disable one version of php, you need to do for php55
config setprop php55-php-fpm status disabled signal-event webapps-update
php setting | ibay property | php.ini property | default | note |
---|---|---|---|---|
- | PHPVersion | - | 74 | can vary upon update if left empty |
allow_url_fopen | AllowUrlfOpen | AllowUrlFopen | off | unsecure keep to off |
allow_url_include | - | - | off | |
auto_prepend_file | AutoPrependFile | - | enabled | /usr/share/php/auth_translation.php unless disabled |
disable_functions | DisabledFunctions | - | system,show_source, symlink,exec,dl,shell_exec,passthru,phpinfo,escapeshellarg,escapeshellcmd | |
display_errors | DisplayErrors | - | off | |
error_log | - | - | /var/log/php/$key/error.log | |
error_reporting | ErrorReporting | - | E_ALL & ~E_NOTICE & ~E_DEPRECATED & ~E_STRICT | |
expose_php | - | ExposePHP | Off | |
file_upload | FileUpload | - | Off | |
mail.add_x_header | - | MailAddXHeader | disabled | only global, not per php version |
mail.force_extra_parameters | MailForceSender | MailForceSender | root@$DomainName | ibayname@$DomainName for ibays |
mail.log | - | MailLog | disabled | |
max_execution_time | MaxExecutionTime | MaxExecutionTime | 30 | |
max_file_uploads | - | MaxFileUpload | 20 | |
max_input_time | MaxInputTime | MaxInputTime | 60 | |
memory_limit | MemoryLimit | MemoryLimit | 128M | |
open_basedir | PHPBaseDir | - | /home/e-smith/files/ibays/IBAYNAME/:/var/lib/php/IBAYNAME/:/usr/share/php/:/usr/share/pear/:/opt/remi/php$version/root/usr/share/pear/:/opt/remi/php$version/root/usr/share/php/ | |
post_max_size | PostMaxSize | PostMaxSize | 20M | |
security.limit_extensions | AllowPHTML | disabled | allow php to interprete more file (.php .htm .html .phar .phtml .xml) | |
sendmail_from | - | MailForceSender | root@$DomainName | |
sendmail_path | - | SendmailPath | /usr/sbin/sendmail -t -i | |
short_open_tag | - | ShortOpenTag | On | |
upload_max_filesize | UploadMaxFilesize | UploadMaxFilesize | 10M |
if you want to set a specific value for an ibay, here we use php80 for ibay MYIBAY and avoid to have any disabled function:
db accounts setprop MYIBAY disable_functions none PHPVersion 80 signal-event webapps-update
Display Error Messages
By default PHP does not display error messages on screen. Some times you get a blank page when executing PHP scripts. Usually some sort of error has occurred, but this error text will not be displayed as SME Server is configured to not display them. Instead the error messages are reported to the log files of the webserver and the general logfile of the server.
Try to analyze your logfiles: /var/log/httpd/error_log and /var/log/httpd/access_log and perhaps also /var/log/messages.
Enable changes for all php versions
If you (for debugging purposes for instance) would like to enable it you can do it with the instructions found below:
mkdir -p /etc/e-smith/templates-custom/etc/php.ini cp /etc/e-smith/templates/etc/php.ini/30ErrorHandling /etc/e-smith/templates-custom/etc/php.ini
After that:
cd /etc/e-smith/templates-custom/etc/php.ini pico 30ErrorHandling
Modify the second line to read:
display_errors = On
After that issue the following commands:
expand-template /etc/php.ini
Depending on your server version use the proper command to restart your webbrowser.
SME Server 7 and newer:
sv t httpd-e-smith
older releases:
/etc/rc7.d/S86httpd-e-smith restart
Now access your page again and see what the error is.
Undo Changes
If everything works you remove the 30ErrorHandling file from the /etc/e-smith/templates-custom/etc/php.ini folder and issue the last two lines again:
expand-template /etc/php.ini /etc/rc7.d/S86httpd-e-smith restart
Enable changes for a specific ibay
Starting SME10 and smeserver-php-3.0.0-39
db accounts setprop MYIBAY DisplayErrors enabled signal-event webapps-update
Open basedir restriction
SME Server has a security measure in place which is called 'open basedir restriction'. This measure prevents PHP from executing or invoking other PHP scripts outside the scope of it's own tree in other words it creates a 'sandbox' or 'jail'. Overall configuration is defined in the php.ini file but you can add an override on a per ibay basis.
Error message
The PHP open basedir restriction usually present to the user like this in the /var/log/messages file:
Aug 12 17:27:42 homer httpd: PHP Warning: main(): open_basedir restriction in effect. File(/tmp/test.php) is not within the allowed path(s): (/home/e-smith/files/ibays/Primary/html/) in /home/e-smith/files/ibays/Primary/html/test.php on line 2
In general you will find this message in the log files only as by default PHP is configured to prevent the display of error messages to the end users. This can be changed as per this HowTo.
Modifying the PHPBaseDir setting for an ibay
-
(Please also see: these instructions on the Useful_Commands page.)
- Open a SME Server shell as root user and document the current setting of the PHPBaseDir directive by writing down the output of the following command: db accounts getprop ibayname PHPBaseDir Be careful to write it down to the letter as we need it in the next step For the Primary ibay the ouptut of above command would normally look like this: /home/e-smith/files/ibays/Primary/html/
- Decide on what directory you would like to add and issue the following: db accounts setprop ibayname PHPBaseDir value Replace ibayname with the name of the ibay and value with the old value for the PHPBaseDir directive you have written down and a colon (:) followed by the full path to the directory you would like to add with a tailing slash (/), e.g. db accounts setprop Primary PHPBaseDir /home/e-smith/files/ibays/Primary/html/:/opt/gallery2/ Above command would allow for invocation of scripts in the /opt/gallery2 path from the Primary ibay html folder by PHP. To allow uploading of files to via http to a ibay name wiki db accounts setprop wiki PHPBaseDir /home/e-smith/files/ibays/wiki/:/tmp/
- After defining the new setting we need to reflect the change in the configuration file of the web server and have the web server reload it's configuration file. This is done by issuing the following command: signal-event ibay-modify ibayname Be sure to replace ibayname with the name of the ibay you have just modified.
Upload_tmp_dir
upload_tmp_dir
Since SME Server V8, you could have sometime an error is thrown by PHP and you will need to specify a temporary directory (e.g. upload_tmp_dir) which is not set in php.ini. see bugzilla:6650 and bugzilla:7652. Many Php applications needs this setting, most of known are wordpress, roudcube, egroupware, etc. Symptoms are that you can't upload contents to the PHP application.
An easy way is to make a Custom Template to resolve this issue. see Uploadtmpdir
PHP 5
SME 7.x uses PHP 4, upgrading to PHP 5 is not recommended and not supported. However, you can add PHP5 as a cgi-bin handler for any given directory on the webserver with the PHP version 5 contrib.
If you really want to upgrade the entire system to PHP 5 (for instance, if you need the mysqli extension), here's how to do it:
yum --enablerepo=centosplus \ install php.i386 php-pear-Net-Socket php-pear-Auth-SASL \ php-pear-DB php-pear-HTTP php-pear-Mail php-pear-XML-Parser /sbin/e-smith/signal-event post-upgrade /sbin/e-smith/signal-event reboot
Horde webmail is confirmed to work under PHP 5, provided you've upgraded to the latest SME version. Please note again that PHP 5 is not officially supported by SME 7.x, and therefore you may run into trouble when upgrading SME (see e.g. http://forums.contribs.org/index.php?topic=38194.0 and http://forums.contribs.org/index.php?topic=39611.0).
See also:
PHP 5 with php-mcrypt
You need php-mcrypt for new WEB applications like eGroupWare, Joomla, etc. So see this Howto:
Tested on my SME Server 7.4 upgraded to SME Server 8.0 Beta 5 and works great !
- Download php-mcrypt rpms needed cd /tmp wget http://rpms.famillecollet.com/enterprise/5/olds/i386/php-common-5.2.10-1.el5.remi.i386.rpm wget http://rpms.famillecollet.com/enterprise/5/olds/i386/php-mcrypt-5.2.10-1.el5.remi.i386.rpm
- Make a backup of your current php.ini file'(because the install will change the file) cp /etc/php.ini /etc/php.ini.org
- Remove the default php-common installed from SME Server Beta 5 (conflict with the new rpm) rpm -e --nodeps php-common-5.2.10-1.el5.sme
- Then install the 2 new rpms yum localinstall php-common-5.2.10-1.el5.remi.i386.rpm php-mcrypt-5.2.10-1.el5.remi.i386.rpm
- Backup the new php.ini file created and restore the original mv /etc/php.ini /etc/php.ini.old mv /etc/php.ini.org /etc/php.ini
- Restart all services svc -t /service/httpd-e-smith
- Check Apache syntax httpd -t