[BUGFIX] Suhosin triggers warnings in Install Tool
[Packages/TYPO3.CMS.git] / typo3 / sysext / install / Classes / SystemEnvironment / Check.php
1 <?php
2 namespace TYPO3\CMS\Install\SystemEnvironment;
3
4 /**
5 * This file is part of the TYPO3 CMS project.
6 *
7 * It is free software; you can redistribute it and/or modify it under
8 * the terms of the GNU General Public License, either version 2
9 * of the License, or any later version.
10 *
11 * For the full copyright and license information, please read the
12 * LICENSE.txt file that was distributed with this source code.
13 *
14 * The TYPO3 project - inspiring people to share!
15 */
16
17 use TYPO3\CMS\Install\Status;
18
19 /**
20 * Check system environment status
21 *
22 * This class is a hardcoded requirement check of the underlying
23 * server and PHP system.
24 *
25 * The class *must not* check for any TYPO3 specific things like
26 * specific configuration values or directories. It should not fail
27 * if there is no TYPO3 at all.
28 *
29 * The only core code used is the class loader
30 *
31 * This class is instantiated as the *very first* class during
32 * installation. It is meant to be *standalone* und must not have
33 * any requirements, except the status classes. It must be possible
34 * to run this script separated from the rest of the core, without
35 * dependencies.
36 *
37 * This means especially:
38 * * No hooks or anything like that
39 * * No usage of *any* TYPO3 code like GeneralUtility
40 * * No require of anything but the status classes
41 * * No localization
42 *
43 * The status messages and title *must not* include HTML, use plain
44 * text only. The return values of this class are not bound to HTML
45 * and can be used in different scopes (eg. as json array).
46 *
47 * @author Christian Kuhn <lolli@schwarzbu.ch>
48 */
49 class Check {
50
51 /**
52 * @var array List of required PHP extensions
53 */
54 protected $requiredPhpExtensions = array(
55 'fileinfo',
56 'filter',
57 'gd',
58 'hash',
59 'json',
60 'mysqli',
61 'openssl',
62 'pcre',
63 'session',
64 'soap',
65 'SPL',
66 'standard',
67 'xml',
68 'zip',
69 'zlib',
70 );
71
72 /**
73 * Get all status information as array with status objects
74 *
75 * @return array<\TYPO3\CMS\Install\Status\StatusInterface>
76 */
77 public function getStatus() {
78 $statusArray = array();
79 $statusArray[] = $this->checkCurrentDirectoryIsInIncludePath();
80 $statusArray[] = $this->checkFileUploadEnabled();
81 $statusArray[] = $this->checkMaximumFileUploadSize();
82 $statusArray[] = $this->checkPostUploadSizeIsHigherOrEqualMaximumFileUploadSize();
83 $statusArray[] = $this->checkMemorySettings();
84 $statusArray[] = $this->checkPhpVersion();
85 $statusArray[] = $this->checkMaxExecutionTime();
86 $statusArray[] = $this->checkDisableFunctions();
87 $statusArray[] = $this->checkDownloadsPossible();
88 $statusArray[] = $this->checkSafeMode();
89 $statusArray[] = $this->checkDocRoot();
90 $statusArray[] = $this->checkOpenBaseDir();
91 $statusArray[] = $this->checkXdebugMaxNestingLevel();
92 $statusArray[] = $this->checkOpenSslInstalled();
93 $statusArray[] = $this->checkSuhosinLoaded();
94 $statusArray[] = $this->checkSuhosinRequestMaxVars();
95 $statusArray[] = $this->checkSuhosinRequestMaxVarnameLength();
96 $statusArray[] = $this->checkSuhosinPostMaxNameLength();
97 $statusArray[] = $this->checkSuhosinPostMaxVars();
98 $statusArray[] = $this->checkSuhosinGetMaxNameLength();
99 $statusArray[] = $this->checkSuhosinGetMaxValueLength();
100 $statusArray[] = $this->checkSuhosinExecutorIncludeWhitelistContainsPhar();
101 $statusArray[] = $this->checkSuhosinExecutorIncludeWhitelistContainsVfs();
102 $statusArray[] = $this->checkSomePhpOpcodeCacheIsLoaded();
103 $statusArray[] = $this->checkReflectionDocComment();
104 $statusArray[] = $this->checkSystemLocale();
105 $statusArray[] = $this->checkLocaleWithUTF8filesystem();
106 $statusArray[] = $this->checkWindowsApacheThreadStackSize();
107 foreach ($this->requiredPhpExtensions as $extension) {
108 $statusArray[] = $this->checkRequiredPhpExtension($extension);
109 }
110 $statusArray[] = $this->checkGdLibTrueColorSupport();
111 $statusArray[] = $this->checkGdLibGifSupport();
112 $statusArray[] = $this->checkGdLibJpgSupport();
113 $statusArray[] = $this->checkGdLibPngSupport();
114 $statusArray[] = $this->checkGdLibFreeTypeSupport();
115 $statusArray[] = $this->checkPhpMagicQuotes();
116 $statusArray[] = $this->checkRegisterGlobals();
117 $statusArray[] = $this->checkLibXmlBug();
118 $statusArray[] = $this->isTrueTypeFontDpiStandard();
119 return $statusArray;
120 }
121
122 /**
123 * Checks if current directory (.) is in PHP include path
124 *
125 * @return Status\StatusInterface
126 */
127 protected function checkCurrentDirectoryIsInIncludePath() {
128 $includePath = ini_get('include_path');
129 $delimiter = $this->isWindowsOs() ? ';' : ':';
130 $pathArray = $this->trimExplode($delimiter, $includePath);
131 if (!in_array('.', $pathArray)) {
132 $status = new Status\WarningStatus();
133 $status->setTitle('Current directory (./) is not within PHP include path');
134 $status->setMessage(
135 'include_path = ' . implode(' ', $pathArray) . LF .
136 'Normally the current path \'.\' is included in the' .
137 ' include_path of PHP. Although TYPO3 does not rely on this,' .
138 ' it is an unusual setting that may introduce problems for' .
139 ' some extensions.'
140 );
141 } else {
142 $status = new Status\OkStatus();
143 $status->setTitle('Current directory (./) is within PHP include path.');
144 }
145 return $status;
146 }
147
148 /**
149 * Check if file uploads are enabled in PHP
150 *
151 * @return Status\StatusInterface
152 */
153 protected function checkFileUploadEnabled() {
154 if (!ini_get('file_uploads')) {
155 $status = new Status\ErrorStatus();
156 $status->setTitle('File uploads not allowed in PHP');
157 $status->setMessage(
158 'file_uploads=' . ini_get('file_uploads') . LF .
159 'TYPO3 uses the ability to upload files from the browser in various cases.' .
160 ' If this flag is disabled in PHP, you won\'t be able to upload files.' .
161 ' But it doesn\'t end here, because not only are files not accepted by' .
162 ' the server - ALL content in the forms are discarded and therefore' .
163 ' nothing at all will be editable if you don\'t set this flag!' .
164 ' However if you cannot enable fileupload for some reason in PHP, alternatively' .
165 ' change the default form encoding value with \\$TYPO3_CONF_VARS[SYS][form_enctype].'
166 );
167 } else {
168 $status = new Status\OkStatus();
169 $status->setTitle('File uploads allowed in PHP');
170 }
171 return $status;
172 }
173
174 /**
175 * Check maximum file upload size against default value of 10MB
176 *
177 * @return Status\StatusInterface
178 */
179 protected function checkMaximumFileUploadSize() {
180 $maximumUploadFilesize = $this->getBytesFromSizeMeasurement(ini_get('upload_max_filesize'));
181 $configuredMaximumUploadFilesize = 1024 * (int)$GLOBALS['TYPO3_CONF_VARS']['BE']['maxFileSize'];
182 if ($maximumUploadFilesize < $configuredMaximumUploadFilesize) {
183 $status = new Status\ErrorStatus();
184 $status->setTitle('PHP Maximum upload filesize too small');
185 $status->setMessage(
186 'PHP upload_max_filesize = ' . (int)($maximumUploadFilesize / 1024) . ' KB' . LF .
187 'TYPO3_CONF_VARS[BE][maxFileSize] = ' . (int)($configuredMaximumUploadFilesize / 1024) . ' KB' . LF . LF .
188 'Currently PHP determines the limits for uploaded file\'s sizes and not TYPO3.' .
189 ' It is recommended that the value of upload_max_filesize is at least equal to the value' .
190 ' of TYPO3_CONF_VARS[BE][maxFileSize].'
191 );
192 } else {
193 $status = new Status\OkStatus();
194 $status->setTitle('PHP Maximum file upload size is higher than or equal to [BE][maxFileSize]');
195 }
196 return $status;
197 }
198
199 /**
200 * Check maximum post upload size correlates with maximum file upload
201 *
202 * @return Status\StatusInterface
203 */
204 protected function checkPostUploadSizeIsHigherOrEqualMaximumFileUploadSize() {
205 $maximumUploadFilesize = $this->getBytesFromSizeMeasurement(ini_get('upload_max_filesize'));
206 $maximumPostSize = $this->getBytesFromSizeMeasurement(ini_get('post_max_size'));
207 if ($maximumPostSize < $maximumUploadFilesize) {
208 $status = new Status\ErrorStatus();
209 $status->setTitle('Maximum size for POST requests is smaller than maximum upload filesize in PHP');
210 $status->setMessage(
211 'upload_max_filesize=' . ini_get('upload_max_filesize') . LF .
212 'post_max_size=' . ini_get('post_max_size') . LF .
213 'You have defined a maximum size for file uploads in PHP which' .
214 ' exceeds the allowed size for POST requests. Therefore the' .
215 ' file uploads can also not be larger than ' . ini_get('post_max_size') . '.'
216 );
217 } else {
218 $status = new Status\OkStatus();
219 $status->setTitle('Maximum post upload size correlates with maximum upload file size in PHP');
220 }
221 return $status;
222 }
223
224 /**
225 * Check memory settings
226 *
227 * @return Status\StatusInterface
228 */
229 protected function checkMemorySettings() {
230 $minimumMemoryLimit = 32;
231 $recommendedMemoryLimit = 64;
232 $memoryLimit = $this->getBytesFromSizeMeasurement(ini_get('memory_limit'));
233 if ($memoryLimit <= 0) {
234 $status = new Status\WarningStatus();
235 $status->setTitle('Unlimited memory limit for PHP');
236 $status->setMessage(
237 'PHP is configured not to limit memory usage at all. This is a risk' .
238 ' and should be avoided in production setup. In general it\'s best practice to limit this.' .
239 ' To be safe, set a limit in PHP, but with a minimum of ' . $recommendedMemoryLimit . 'MB:' . LF .
240 'memory_limit=' . $recommendedMemoryLimit . 'M'
241 );
242 } elseif ($memoryLimit < 1024 * 1024 * $minimumMemoryLimit) {
243 $status = new Status\ErrorStatus();
244 $status->setTitle('PHP Memory limit below ' . $minimumMemoryLimit . 'MB');
245 $status->setMessage(
246 'memory_limit=' . ini_get('memory_limit') . LF .
247 'Your system is configured to enforce a memory limit for PHP scripts lower than ' .
248 $minimumMemoryLimit . 'MB. It is required to raise the limit.' .
249 ' We recommend a minimum PHP memory limit of ' . $recommendedMemoryLimit . 'MB:' . LF .
250 'memory_limit=' . $recommendedMemoryLimit . 'M'
251 );
252 } elseif ($memoryLimit < 1024 * 1024 * $recommendedMemoryLimit) {
253 $status = new Status\WarningStatus();
254 $status->setTitle('PHP Memory limit below ' . $recommendedMemoryLimit . 'MB');
255 $status->setMessage(
256 'memory_limit=' . ini_get('memory_limit') . LF .
257 'Your system is configured to enforce a memory limit for PHP scripts lower than ' .
258 $recommendedMemoryLimit . 'MB.' .
259 ' A slim TYPO3 instance without many extensions will probably work, but you should monitor your' .
260 ' system for "allowed memory size of X bytes exhausted" messages, especially if using the backend.' .
261 ' To be on the safe side,' . ' we recommend a minimum PHP memory limit of ' .
262 $recommendedMemoryLimit . 'MB:' . LF .
263 'memory_limit=' . $recommendedMemoryLimit . 'M'
264 );
265 } else {
266 $status = new Status\OkStatus();
267 $status->setTitle('PHP Memory limit is equal to or more than ' . $recommendedMemoryLimit . 'MB');
268 }
269 return $status;
270 }
271
272 /**
273 * Check minimum PHP version
274 *
275 * @return Status\StatusInterface
276 */
277 protected function checkPhpVersion() {
278 $minimumPhpVersion = '5.3.7';
279 $currentPhpVersion = phpversion();
280 if (version_compare($currentPhpVersion, $minimumPhpVersion) < 0) {
281 $status = new Status\ErrorStatus();
282 $status->setTitle('PHP version too low');
283 $status->setMessage(
284 'Your PHP version ' . $currentPhpVersion . ' is too old. TYPO3 CMS does not run' .
285 ' with this version. Update to at least PHP ' . $minimumPhpVersion
286 );
287 } else {
288 $status = new Status\OkStatus();
289 $status->setTitle('PHP version is fine');
290 }
291 return $status;
292 }
293
294 /**
295 * Check maximum execution time
296 *
297 * @return Status\StatusInterface
298 */
299 protected function checkMaxExecutionTime() {
300 $minimumMaximumExecutionTime = 30;
301 $recommendedMaximumExecutionTime = 240;
302 $currentMaximumExecutionTime = ini_get('max_execution_time');
303 if ($currentMaximumExecutionTime == 0) {
304 if (PHP_SAPI === 'cli') {
305 $status = new Status\OkStatus();
306 $status->setTitle('Infinite PHP script execution time');
307 $status->setMessage(
308 'Maximum PHP script execution time is always set to infinite (0) in cli mode.' .
309 ' The setting used for web requests cannot be checked from command line.'
310 );
311 } else {
312 $status = new Status\WarningStatus();
313 $status->setTitle('Infinite PHP script execution time');
314 $status->setMessage(
315 'max_execution_time=' . $currentMaximumExecutionTime . LF .
316 'While TYPO3 is fine with this, you risk a denial-of-service for your system if for whatever' .
317 ' reason some script hangs in an infinite loop. You are usually on the safe side ' .
318 ' if it is reduced to ' . $recommendedMaximumExecutionTime . ' seconds:' . LF .
319 'max_execution_time=' . $recommendedMaximumExecutionTime
320 );
321 }
322 } elseif ($currentMaximumExecutionTime < $minimumMaximumExecutionTime) {
323 $status = new Status\ErrorStatus();
324 $status->setTitle('Low PHP script execution time');
325 $status->setMessage(
326 'max_execution_time=' . $currentMaximumExecutionTime . LF .
327 'Your max_execution_time is too low. Some expensive operations in TYPO3 can take longer than that.' .
328 ' It is recommended to raise the limit to ' . $recommendedMaximumExecutionTime . ' seconds:' . LF .
329 'max_execution_time=' . $recommendedMaximumExecutionTime
330 );
331 } elseif ($currentMaximumExecutionTime < $recommendedMaximumExecutionTime) {
332 $status = new Status\WarningStatus();
333 $status->setTitle('Low PHP script execution time');
334 $status->setMessage(
335 'max_execution_time=' . $currentMaximumExecutionTime . LF .
336 'Your max_execution_time is low. While TYPO3 often runs without problems' .
337 ' with ' . $minimumMaximumExecutionTime . ' seconds,' .
338 ' it may still happen that script execution is stopped before finishing' .
339 ' calculations. You should monitor the system for messages in this area' .
340 ' and maybe raise the limit to ' . $recommendedMaximumExecutionTime . ' seconds:' . LF .
341 'max_execution_time=' . $recommendedMaximumExecutionTime
342 );
343 } else {
344 $status = new Status\OkStatus();
345 $status->setTitle('Maximum PHP script execution time is equal to or more than '
346 . $recommendedMaximumExecutionTime);
347 }
348 return $status;
349 }
350
351 /**
352 * Check for disabled functions
353 *
354 * @return Status\StatusInterface
355 */
356 protected function checkDisableFunctions() {
357 $disabledFunctions = trim(ini_get('disable_functions'));
358
359 // Filter "disable_functions"
360 $disabledFunctionsArray = $this->trimExplode(',', $disabledFunctions);
361
362 // Array with strings to find
363 $findStrings = array(
364 // Disabled by default on Ubuntu OS but this is okay since the Core does not use them
365 'pcntl_',
366 );
367 foreach ($disabledFunctionsArray as $key => $disabledFunction) {
368 foreach ($findStrings as $findString) {
369 if (strpos($disabledFunction, $findString) !== FALSE) {
370 unset($disabledFunctionsArray[$key]);
371 }
372 }
373 }
374
375 if (strlen($disabledFunctions) > 0 && count($disabledFunctionsArray) > 0) {
376 $status = new Status\ErrorStatus();
377 $status->setTitle('Some PHP functions disabled');
378 $status->setMessage(
379 'disable_functions=' . implode(' ', explode(',', $disabledFunctions)) . LF .
380 'These function(s) are disabled. TYPO3 uses some of those, so there might be trouble.' .
381 ' TYPO3 is designed to use the default set of PHP functions plus some common extensions.' .
382 ' Possibly these functions are disabled' .
383 ' due to security considerations and most likely the list would include a function like' .
384 ' exec() which is used by TYPO3 at various places. Depending on which exact functions' .
385 ' are disabled, some parts of the system may just break without further notice.'
386 );
387 } elseif (strlen($disabledFunctions) > 0 && count($disabledFunctionsArray) === 0) {
388 $status = new Status\NoticeStatus();
389 $status->setTitle('Some PHP functions currently disabled but OK');
390 $status->setMessage(
391 'disable_functions=' . implode(' ', explode(',', $disabledFunctions)) . LF .
392 'These function(s) are disabled. TYPO3 uses currently none of those, so you are good to go.'
393 );
394 } else {
395 $status = new Status\OkStatus();
396 $status->setTitle('No disabled PHP functions');
397 }
398 return $status;
399 }
400
401 /**
402 * Check if it is possible to download external data (e.g. TER)
403 * Either allow_url_fopen must be enabled or curl must be used
404 *
405 * @return Status\OkStatus|Status\WarningStatus
406 */
407 protected function checkDownloadsPossible() {
408 $allowUrlFopen = (bool)ini_get('allow_url_fopen');
409 $curlEnabled = !empty($GLOBALS['TYPO3_CONF_VARS']['SYS']['curlUse']);
410 if ($allowUrlFopen || $curlEnabled) {
411 $status = new Status\OkStatus();
412 $status->setTitle('Fetching external URLs is allowed');
413 } else {
414 $status = new Status\WarningStatus();
415 $status->setTitle('Fetching external URLs is not allowed');
416 $status->setMessage(
417 'Either enable PHP runtime setting "allow_url_fopen"' . LF . 'or enable curl by setting [SYS][curlUse] accordingly.'
418 );
419 }
420 return $status;
421 }
422
423 /**
424 * Check if safe mode is enabled
425 *
426 * @return Status\StatusInterface
427 */
428 protected function checkSafeMode() {
429 $safeModeEnabled = FALSE;
430 if (version_compare(phpversion(), '5.4', '<')) {
431 $safeModeEnabled = filter_var(
432 ini_get('safe_mode'),
433 FILTER_VALIDATE_BOOLEAN,
434 array(FILTER_REQUIRE_SCALAR, FILTER_NULL_ON_FAILURE)
435 );
436 }
437 if ($safeModeEnabled) {
438 $status = new Status\ErrorStatus();
439 $status->setTitle('PHP safe mode on');
440 $status->setMessage(
441 'PHP safe_mode enabled. This is unsupported by TYPO3 CMS, it must be turned off:' . LF .
442 'safe_mode=Off'
443 );
444 } else {
445 $status = new Status\OkStatus();
446 $status->setTitle('PHP safe mode off');
447 }
448 return $status;
449 }
450
451 /**
452 * Check for doc_root ini setting
453 *
454 * @return Status\StatusInterface
455 */
456 protected function checkDocRoot() {
457 $docRootSetting = trim(ini_get('doc_root'));
458 if (strlen($docRootSetting) > 0) {
459 $status = new Status\NoticeStatus();
460 $status->setTitle('doc_root is set');
461 $status->setMessage(
462 'doc_root=' . $docRootSetting . LF .
463 'PHP cannot execute scripts' .
464 ' outside this directory. This setting is seldom used and must correlate' .
465 ' with your actual document root. You might be in trouble if your' .
466 ' TYPO3 CMS core code is linked to some different location.' .
467 ' If that is a problem, the setting must be changed.'
468 );
469 } else {
470 $status = new Status\OkStatus();
471 $status->setTitle('PHP doc_root is not set');
472 }
473 return $status;
474 }
475
476 /**
477 * Check open_basedir
478 *
479 * @return Status\StatusInterface
480 */
481 protected function checkOpenBaseDir() {
482 $openBaseDirSetting = trim(ini_get('open_basedir'));
483 if (strlen($openBaseDirSetting) > 0) {
484 $status = new Status\NoticeStatus();
485 $status->setTitle('PHP open_basedir is set');
486 $status->setMessage(
487 'open_basedir = ' . ini_get('open_basedir') . LF .
488 'This restricts TYPO3 to open and include files only in this' .
489 ' path. Please make sure that this does not prevent TYPO3 from running,' .
490 ' if for example your TYPO3 CMS core is linked to a different directory' .
491 ' not included in this path.'
492 );
493 } else {
494 $status = new Status\OkStatus();
495 $status->setTitle('PHP open_basedir is off');
496 }
497 return $status;
498 }
499
500 /**
501 * If xdebug is loaded, the default max_nesting_level of 100 must be raised
502 *
503 * @return Status\StatusInterface
504 */
505 protected function checkXdebugMaxNestingLevel() {
506 if (extension_loaded('xdebug')) {
507 $recommendedMaxNestingLevel = 400;
508 $errorThreshold = 250;
509 $currentMaxNestingLevel = ini_get('xdebug.max_nesting_level');
510 if ($currentMaxNestingLevel < $errorThreshold) {
511 $status = new Status\ErrorStatus();
512 $status->setTitle('PHP xdebug.max_nesting_level is critically low');
513 $status->setMessage(
514 'xdebug.max_nesting_level=' . $currentMaxNestingLevel . LF .
515 'This setting controls the maximum number of nested function calls to protect against' .
516 ' infinite recursion. The current value is too low for TYPO3 CMS and must' .
517 ' be either raised or xdebug has to be unloaded. A value of ' . $recommendedMaxNestingLevel .
518 ' is recommended. Warning: Expect fatal PHP errors in central parts of the CMS' .
519 ' if the value is not raised significantly to:' . LF .
520 'xdebug.max_nesting_level=' . $recommendedMaxNestingLevel
521 );
522 } elseif ($currentMaxNestingLevel < $recommendedMaxNestingLevel) {
523 $status = new Status\WarningStatus();
524 $status->setTitle('PHP xdebug.max_nesting_level is low');
525 $status->setMessage(
526 'xdebug.max_nesting_level=' . $currentMaxNestingLevel . LF .
527 'This setting controls the maximum number of nested function calls to protect against' .
528 ' infinite recursion. The current value is high enough for the TYPO3 CMS core to work' .
529 ' fine, but still some extensions could raise fatal PHP errors if the setting is not' .
530 ' raised further. A value of ' . $recommendedMaxNestingLevel . ' is recommended.' . LF .
531 'xdebug.max_nesting_level=' . $recommendedMaxNestingLevel
532 );
533 } else {
534 $status = new Status\OkStatus();
535 $status->setTitle('PHP xdebug.max_nesting_level ok');
536 }
537 } else {
538 $status = new Status\OkStatus();
539 $status->setTitle('PHP xdebug extension not loaded');
540 }
541 return $status;
542 }
543
544 /**
545 * Check accessibility and functionality of OpenSSL
546 *
547 * @return Status\StatusInterface
548 */
549 protected function checkOpenSslInstalled() {
550 if (extension_loaded('openssl')) {
551 $testKey = @openssl_pkey_new();
552 if (is_resource($testKey)) {
553 openssl_free_key($testKey);
554 $status = new Status\OkStatus();
555 $status->setTitle('PHP OpenSSL extension installed properly');
556 } else {
557 $status = new Status\ErrorStatus();
558 $status->setTitle('PHP OpenSSL extension not working');
559 $status->setMessage(
560 'Something went wrong while trying to create a new private key for testing.' .
561 ' Please check the integration of the PHP OpenSSL extension and if it is installed correctly.'
562 );
563 }
564 } else {
565 $status = new Status\ErrorStatus();
566 $status->setTitle('PHP OpenSSL extension not loaded');
567 $status->setMessage(
568 'OpenSSL is a PHP extension to encrypt/decrypt data between requests.' .
569 ' TYPO3 CMS requires it to be able to encrypt stored passwords to improve the security in the' .
570 ' database layer.'
571 );
572 }
573
574 return $status;
575 }
576
577 /**
578 * Check enabled suhosin
579 *
580 * @return Status\StatusInterface
581 */
582 protected function checkSuhosinLoaded() {
583 if ($this->isSuhosinLoadedAndActive()) {
584 $status = new Status\OkStatus();
585 $status->setTitle('PHP suhosin extension loaded and active');
586 } else {
587 $status = new Status\NoticeStatus();
588 $status->setTitle('PHP suhosin extension not loaded or in simulation mode');
589 $status->setMessage(
590 'suhosin is an extension to harden the PHP environment. In general, it is' .
591 ' good to have it from a security point of view. While TYPO3 CMS works' .
592 ' fine with suhosin, it has some requirements different from the default settings' .
593 ' to be set if enabled.'
594 );
595 }
596 return $status;
597 }
598
599 /**
600 * Check suhosin.request.max_vars
601 *
602 * @return Status\StatusInterface
603 */
604 protected function checkSuhosinRequestMaxVars() {
605 $recommendedRequestMaxVars = 400;
606 if ($this->isSuhosinLoadedAndActive()) {
607 $currentRequestMaxVars = ini_get('suhosin.request.max_vars');
608 if ($currentRequestMaxVars < $recommendedRequestMaxVars) {
609 $status = new Status\ErrorStatus();
610 $status->setTitle('PHP suhosin.request.max_vars too low');
611 $status->setMessage(
612 'suhosin.request.max_vars=' . $currentRequestMaxVars . LF .
613 'This setting can lead to lost information if submitting forms with lots of data in TYPO3 CMS' .
614 ' (as the install tool does). It is highly recommended to raise this' .
615 ' to at least ' . $recommendedRequestMaxVars . ':' . LF .
616 'suhosin.request.max_vars=' . $recommendedRequestMaxVars
617 );
618 } else {
619 $status = new Status\OkStatus();
620 $status->setTitle('PHP suhosin.request.max_vars ok');
621 }
622 } else {
623 $status = new Status\InfoStatus();
624 $status->setTitle('Suhosin not loaded');
625 $status->setMessage(
626 'If enabling suhosin, suhosin.request.max_vars' .
627 ' should be set to at least ' . $recommendedRequestMaxVars . ':' . LF .
628 'suhosin.request.max_vars=' . $recommendedRequestMaxVars
629 );
630 }
631 return $status;
632 }
633
634 /**
635 * Check suhosin.request.max_varname_length
636 *
637 * @return Status\StatusInterface
638 */
639 protected function checkSuhosinRequestMaxVarnameLength() {
640 $recommendedRequestMaxVarnameLength = 200;
641 if ($this->isSuhosinLoadedAndActive()) {
642 $currentRequestMaxVarnameLength = ini_get('suhosin.request.max_varname_length');
643 if ($currentRequestMaxVarnameLength < $recommendedRequestMaxVarnameLength) {
644 $status = new Status\ErrorStatus();
645 $status->setTitle('PHP suhosin.request.max_varname_length too low');
646 $status->setMessage(
647 'suhosin.request.max_varname_length=' . $currentRequestMaxVarnameLength . LF .
648 'This setting can lead to lost information if submitting forms with lots of data in TYPO3 CMS' .
649 ' (as the install tool does). It is highly recommended to raise this' .
650 ' to at least ' . $recommendedRequestMaxVarnameLength . ':' . LF .
651 'suhosin.request.max_varname_length=' . $recommendedRequestMaxVarnameLength
652 );
653 } else {
654 $status = new Status\OkStatus();
655 $status->setTitle('PHP suhosin.request.max_varname_length ok');
656 }
657 } else {
658 $status = new Status\InfoStatus();
659 $status->setTitle('Suhosin not loaded');
660 $status->setMessage(
661 'If enabling suhosin, suhosin.request.max_varname_length' .
662 ' should be set to at least ' . $recommendedRequestMaxVarnameLength . ':' . LF .
663 'suhosin.request.max_varname_length=' . $recommendedRequestMaxVarnameLength
664 );
665 }
666 return $status;
667 }
668
669 /**
670 * Check suhosin.post.max_name_length
671 *
672 * @return Status\StatusInterface
673 */
674 protected function checkSuhosinPostMaxNameLength() {
675 $recommendedPostMaxNameLength = 200;
676 if ($this->isSuhosinLoadedAndActive()) {
677 $currentPostMaxNameLength = ini_get('suhosin.post.max_name_length');
678 if ($currentPostMaxNameLength < $recommendedPostMaxNameLength) {
679 $status = new Status\ErrorStatus();
680 $status->setTitle('PHP suhosin.post.max_name_length too low');
681 $status->setMessage(
682 'suhosin.post.max_name_length=' . $currentPostMaxNameLength . LF .
683 'This setting can lead to lost information if submitting forms with lots of data in TYPO3 CMS' .
684 ' (as the install tool does). It is highly recommended to raise this' .
685 ' to at least ' . $recommendedPostMaxNameLength . ':' . LF .
686 'suhosin.post.max_name_length=' . $recommendedPostMaxNameLength
687 );
688 } else {
689 $status = new Status\OkStatus();
690 $status->setTitle('PHP suhosin.post.max_name_length ok');
691 }
692 } else {
693 $status = new Status\InfoStatus();
694 $status->setTitle('Suhosin not loaded');
695 $status->setMessage(
696 'If enabling suhosin, suhosin.post.max_name_length' .
697 ' should be set to at least ' . $recommendedPostMaxNameLength . ':' . LF .
698 'suhosin.post.max_name_length=' . $recommendedPostMaxNameLength
699 );
700 }
701 return $status;
702 }
703
704 /**
705 * Check suhosin.post.max_vars
706 *
707 * @return Status\StatusInterface
708 */
709 protected function checkSuhosinPostMaxVars() {
710 $recommendedPostMaxVars = 400;
711 if ($this->isSuhosinLoadedAndActive()) {
712 $currentPostMaxVars = ini_get('suhosin.post.max_vars');
713 if ($currentPostMaxVars < $recommendedPostMaxVars) {
714 $status = new Status\ErrorStatus();
715 $status->setTitle('PHP suhosin.post.max_vars too low');
716 $status->setMessage(
717 'suhosin.post.max_vars=' . $currentPostMaxVars . LF .
718 'This setting can lead to lost information if submitting forms with lots of data in TYPO3 CMS' .
719 ' (as the install tool does). It is highly recommended to raise this' .
720 ' to at least ' . $recommendedPostMaxVars . ':' . LF .
721 'suhosin.post.max_vars=' . $recommendedPostMaxVars
722 );
723 } else {
724 $status = new Status\OkStatus();
725 $status->setTitle('PHP suhosin.post.max_vars ok');
726 }
727 } else {
728 $status = new Status\InfoStatus();
729 $status->setTitle('Suhosin not loaded');
730 $status->setMessage(
731 'If enabling suhosin, suhosin.post.max_vars' .
732 ' should be set to at least ' . $recommendedPostMaxVars . ':' . LF .
733 'suhosin.post.max_vars=' . $recommendedPostMaxVars
734 );
735 }
736 return $status;
737 }
738
739 /**
740 * Check suhosin.get.max_value_length
741 *
742 * @return Status\StatusInterface
743 */
744 protected function checkSuhosinGetMaxValueLength() {
745 $recommendedGetMaxValueLength = 2000;
746 if ($this->isSuhosinLoadedAndActive()) {
747 $currentGetMaxValueLength = ini_get('suhosin.get.max_value_length');
748 if ($currentGetMaxValueLength < $recommendedGetMaxValueLength) {
749 $status = new Status\ErrorStatus();
750 $status->setTitle('PHP suhosin.get.max_value_length too low');
751 $status->setMessage(
752 'suhosin.get.max_value_length=' . $currentGetMaxValueLength . LF .
753 'This setting can lead to lost information if submitting forms with lots of data in TYPO3 CMS' .
754 ' (as the install tool does). It is highly recommended to raise this' .
755 ' to at least ' . $recommendedGetMaxValueLength . ':' . LF .
756 'suhosin.get.max_value_length=' . $recommendedGetMaxValueLength
757 );
758 } else {
759 $status = new Status\OkStatus();
760 $status->setTitle('PHP suhosin.get.max_value_length ok');
761 }
762 } else {
763 $status = new Status\InfoStatus();
764 $status->setTitle('Suhosin not loaded');
765 $status->setMessage(
766 'If enabling suhosin, suhosin.get.max_value_length' .
767 ' should be set to at least ' . $recommendedGetMaxValueLength . ':' . LF .
768 'suhosin.get.max_value_length=' . $recommendedGetMaxValueLength
769 );
770 }
771 return $status;
772 }
773
774 /**
775 * Check suhosin.get.max_name_length
776 *
777 * @return Status\StatusInterface
778 */
779 protected function checkSuhosinGetMaxNameLength() {
780 $recommendedGetMaxNameLength = 200;
781 if ($this->isSuhosinLoadedAndActive()) {
782 $currentGetMaxNameLength = ini_get('suhosin.get.max_name_length');
783 if ($currentGetMaxNameLength < $recommendedGetMaxNameLength) {
784 $status = new Status\ErrorStatus();
785 $status->setTitle('PHP suhosin.get.max_name_length too low');
786 $status->setMessage(
787 'suhosin.get.max_name_length=' . $currentGetMaxNameLength . LF .
788 'This setting can lead to lost information if submitting forms with lots of data in TYPO3 CMS' .
789 ' (as the install tool does). It is highly recommended to raise this' .
790 ' to at least ' . $recommendedGetMaxNameLength . ':' . LF .
791 'suhosin.get.max_name_length=' . $recommendedGetMaxNameLength
792 );
793 } else {
794 $status = new Status\OkStatus();
795 $status->setTitle('PHP suhosin.get.max_name_length ok');
796 }
797 } else {
798 $status = new Status\InfoStatus();
799 $status->setTitle('Suhosin not loaded');
800 $status->setMessage(
801 'If enabling suhosin, suhosin.get.max_name_length' .
802 ' should be set to at least ' . $recommendedGetMaxNameLength . ':' . LF .
803 'suhosin.get.max_name_length=' . $recommendedGetMaxNameLength
804 );
805 }
806 return $status;
807 }
808
809 /**
810 * Check suhosin.executor.include.whitelist contains phar
811 *
812 * @return Status\StatusInterface
813 */
814 protected function checkSuhosinExecutorIncludeWhiteListContainsPhar() {
815 if ($this->isSuhosinLoadedAndActive()) {
816 $whitelist = (string)ini_get('suhosin.executor.include.whitelist');
817 if (strpos($whitelist, 'phar') === FALSE) {
818 $status = new Status\NoticeStatus();
819 $status->setTitle('PHP suhosin.executor.include.whitelist does not contain phar');
820 $status->setMessage(
821 'suhosin.executor.include.whitelist= ' . $whitelist . LF .
822 '"phar" is currently not a hard requirement of TYPO3 CMS but is nice to have and a possible' .
823 ' requirement in future versions. A useful setting is:' . LF .
824 'suhosin.executor.include.whitelist=phar,vfs'
825 );
826 } else {
827 $status = new Status\OkStatus();
828 $status->setTitle('PHP suhosin.executor.include.whitelist contains phar');
829 }
830 } else {
831 $status = new Status\InfoStatus();
832 $status->setTitle('Suhosin not loaded');
833 $status->setMessage(
834 'If enabling suhosin, a useful setting is:' . LF .
835 'suhosin.executor.include.whitelist=phar,vfs'
836 );
837 }
838 return $status;
839 }
840
841 /**
842 * Check suhosin.executor.include.whitelist contains vfs
843 *
844 * @return Status\StatusInterface
845 */
846 protected function checkSuhosinExecutorIncludeWhiteListContainsVfs() {
847 if ($this->isSuhosinLoadedAndActive()) {
848 $whitelist = (string)ini_get('suhosin.executor.include.whitelist');
849 if (strpos($whitelist, 'vfs') === FALSE) {
850 $status = new Status\WarningStatus();
851 $status->setTitle('PHP suhosin.executor.include.whitelist does not contain vfs');
852 $status->setMessage(
853 'suhosin.executor.include.whitelist= ' . $whitelist . LF .
854 '"vfs" is currently not a hard requirement of TYPO3 CMS but tons of unit tests rely on it.' .
855 ' Furthermore, vfs will likely be a base for an additional compatibility layer in the future.' .
856 ' A useful setting is:' . LF .
857 'suhosin.executor.include.whitelist=phar,vfs'
858 );
859 } else {
860 $status = new Status\OkStatus();
861 $status->setTitle('PHP suhosin.executor.include.whitelist contains vfs');
862 }
863 } else {
864 $status = new Status\InfoStatus();
865 $status->setTitle('Suhosin not loaded');
866 $status->setMessage(
867 'If enabling suhosin, a useful setting is:' . LF .
868 'suhosin.executor.include.whitelist=phar,vfs'
869 );
870 }
871 return $status;
872 }
873
874 /**
875 * Check if some opcode cache is loaded
876 *
877 * @return Status\StatusInterface
878 */
879 protected function checkSomePhpOpcodeCacheIsLoaded() {
880 // Link to our wiki page, so we can update opcode cache issue information independent of TYPO3 CMS releases.
881 $wikiLink = 'For more information take a look in our wiki ' . TYPO3_URL_WIKI_OPCODECACHE . '.';
882 $opcodeCaches = \TYPO3\CMS\Core\Utility\OpcodeCacheUtility::getAllActive();
883 if (count($opcodeCaches) === 0) {
884 // Set status to notice. It needs to be notice so email won't be triggered.
885 $status = new Status\NoticeStatus();
886 $status->setTitle('No PHP opcode cache loaded');
887 $status->setMessage(
888 'PHP opcode caches hold a compiled version of executed PHP scripts in' .
889 ' memory and do not require to recompile a script each time it is accessed.' .
890 ' This can be a massive performance improvement and can reduce the load on a' .
891 ' server in general. A parse time reduction by factor three for fully cached' .
892 ' pages can be achieved easily if using an opcode cache.' .
893 LF . $wikiLink
894 );
895 } else {
896 $status = new Status\OkStatus();
897 $message = '';
898
899 foreach ($opcodeCaches as $opcodeCache => $properties) {
900 $message .= 'Name: ' . $opcodeCache . ' Version: ' . $properties['version'];
901 $message .= LF;
902
903 if ($properties['error']) {
904 // Set status to error if not already set
905 if ($status->getSeverity() !== 'error') {
906 $status = new Status\ErrorStatus();
907 }
908 $message .= ' This opcode cache is marked as malfunctioning by the TYPO3 CMS Team.';
909 } elseif ($properties['canInvalidate']) {
910 $message .= ' This opcode cache should work correctly and has good performance.';
911 } else {
912 // Set status to notice if not already error set. It needs to be notice so email won't be triggered.
913 if ($status->getSeverity() !== 'error' || $status->getSeverity() !== 'warning') {
914 $status = new Status\NoticeStatus();
915 }
916 $message .= ' This opcode cache may work correctly but has medium performance.';
917 }
918 $message .= LF;
919 }
920
921 $message .= $wikiLink;
922
923 // Set title of status depending on serverity
924 switch ($status->getSeverity()) {
925 case 'error':
926 $status->setTitle('A possibly malfunctioning PHP opcode cache is loaded');
927 break;
928 case 'warning':
929 $status->setTitle('A PHP opcode cache is loaded which may cause problems');
930 break;
931 case 'ok':
932 default:
933 $status->setTitle('A PHP opcode cache is loaded');
934 break;
935 }
936 $status->setMessage($message);
937 }
938 return $status;
939 }
940
941 /**
942 * Check doc comments can be fetched by reflection
943 *
944 * @return Status\StatusInterface
945 */
946 protected function checkReflectionDocComment() {
947 $testReflection = new \ReflectionMethod(get_class($this), __FUNCTION__);
948 if ($testReflection->getDocComment() === FALSE) {
949 $status = new Status\AlertStatus();
950 $status->setTitle('PHP Doc comment reflection broken');
951 $status->setMessage(
952 'TYPO3 CMS core extensions like extbase and fluid heavily rely on method'
953 . ' comment parsing to fetch annotations and add magic belonging to them.'
954 . ' This does not work in the current environment and so we cannot install'
955 . ' TYPO3 CMS.' . LF
956 . ' Here are some possibilities: ' . LF
957 . '* In Zend OPcache you can disable saving/loading comments. If you are using'
958 . ' Zend OPcache (included since PHP 5.5) then check your php.ini settings for'
959 . ' opcache.save_comments and opcache.load_comments and enable them.' . LF
960 . '* In Zend Optimizer+ you can disable saving comments. If you are using'
961 . ' Zend Optimizer+ then check your php.ini settings for'
962 . ' zend_optimizerplus.save_comments and enable it.' . LF
963 . '* The PHP extension eaccelerator is known to break this if'
964 . ' it is compiled without --with-eaccelerator-doc-comment-inclusion flag.'
965 . ' This compile flag must be specified, otherwise TYPO3 CMS will not work.' . LF
966 . 'For more information take a look in our wiki ' . TYPO3_URL_WIKI_OPCODECACHE . '.'
967 );
968 } else {
969 $status = new Status\OkStatus();
970 $status->setTitle('PHP Doc comment reflection works');
971 }
972 return $status;
973 }
974
975 /**
976 * Check if systemLocale setting is correct (locale exists in the OS)
977 *
978 * @return Status\StatusInterface
979 */
980 protected function checkSystemLocale() {
981
982 $currentLocale = setlocale(LC_CTYPE, 0);
983
984 // On Windows an empty locale value uses the regional settings from the Control Panel
985 if ($GLOBALS['TYPO3_CONF_VARS']['SYS']['systemLocale'] === '' && TYPO3_OS !== 'WIN') {
986 $status = new Status\InfoStatus();
987 $status->setTitle('Empty systemLocale setting');
988 $status->setMessage(
989 '$GLOBALS[TYPO3_CONF_VARS][SYS][systemLocale] is not set. This is fine as long as no UTF-8' .
990 ' file system is used.'
991 );
992 } elseif (setlocale(LC_CTYPE, $GLOBALS['TYPO3_CONF_VARS']['SYS']['systemLocale']) === FALSE) {
993 $status = new Status\ErrorStatus();
994 $status->setTitle('Incorrect systemLocale setting');
995 $status->setMessage(
996 'Current value of the $GLOBALS[TYPO3_CONF_VARS][SYS][systemLocale] is incorrect. A locale with' .
997 ' this name doesn\'t exist in the operating system.'
998 );
999 setlocale(LC_CTYPE, $currentLocale);
1000 } else {
1001 $status = new Status\OkStatus();
1002 $status->setTitle('System locale is correct');
1003 }
1004
1005 return $status;
1006 }
1007
1008 /**
1009 * Checks whether we can use file names with UTF-8 characters.
1010 * Configured system locale must support UTF-8 when UTF8filesystem is set
1011 *
1012 * @return Status\StatusInterface
1013 */
1014 protected function checkLocaleWithUTF8filesystem() {
1015
1016 if ($GLOBALS['TYPO3_CONF_VARS']['SYS']['UTF8filesystem']) {
1017
1018 // On Windows an empty local value uses the regional settings from the Control Panel
1019 if ($GLOBALS['TYPO3_CONF_VARS']['SYS']['systemLocale'] === '' && TYPO3_OS !== 'WIN') {
1020 $status = new Status\ErrorStatus();
1021 $status->setTitle('System locale not set on UTF-8 file system');
1022 $status->setMessage(
1023 '$GLOBALS[TYPO3_CONF_VARS][SYS][UTF8filesystem] is set, but $GLOBALS[TYPO3_CONF_VARS][SYS][systemLocale]' .
1024 ' is empty. Make sure a valid locale which supports UTF-8 is set.'
1025 );
1026 } else {
1027 $testString = 'ÖöĄĆŻĘĆćążąęó.jpg';
1028 $currentLocale = setlocale(LC_CTYPE, 0);
1029 $quote = TYPO3_OS === 'WIN' ? '"' : '\'';
1030
1031 setlocale(LC_CTYPE, $GLOBALS['TYPO3_CONF_VARS']['SYS']['systemLocale']);
1032
1033 if (escapeshellarg($testString) === $quote . $testString . $quote) {
1034 $status = new Status\OkStatus();
1035 $status->setTitle('File names with UTF-8 characters can be used.');
1036 } else {
1037 $status = new Status\ErrorStatus();
1038 $status->setTitle('System locale setting doesn\'t support UTF-8 file names.');
1039 $status->setMessage(
1040 'Please check your $GLOBALS[TYPO3_CONF_VARS][SYS][systemLocale] setting.'
1041 );
1042 }
1043
1044 setlocale(LC_CTYPE, $currentLocale);
1045 }
1046
1047
1048 } else {
1049 $status = new Status\OkStatus();
1050 $status->setTitle('Skipping test, as UTF8filesystem is not enabled.');
1051 }
1052
1053 return $status;
1054 }
1055
1056 /**
1057 * Checks thread stack size if on windows with apache
1058 *
1059 * @return Status\StatusInterface
1060 */
1061 protected function checkWindowsApacheThreadStackSize() {
1062 if (
1063 $this->isWindowsOs()
1064 && substr($_SERVER['SERVER_SOFTWARE'], 0, 6) === 'Apache'
1065 ) {
1066 $status = new Status\WarningStatus();
1067 $status->setTitle('Windows apache thread stack size');
1068 $status->setMessage(
1069 'This current value cannot be checked by the system, so please ignore this warning if it' .
1070 ' is already taken care of: Fluid uses complex regular expressions which require a lot' .
1071 ' of stack space during the first processing.' .
1072 ' On Windows the default stack size for Apache is a lot smaller than on UNIX.' .
1073 ' You can increase the size to 8MB (default on UNIX) by adding the following configuration' .
1074 ' to httpd.conf and restarting Apache afterwards:' . LF .
1075 '<IfModule mpm_winnt_module>' . LF .
1076 'ThreadStackSize 8388608' . LF .
1077 '</IfModule>'
1078 );
1079 } else {
1080 $status = new Status\OkStatus();
1081 $status->setTitle('Apache ThreadStackSize is not an issue on UNIX systems');
1082 }
1083 return $status;
1084 }
1085
1086 /**
1087 * Check if a specific required PHP extension is loaded
1088 *
1089 * @param string $extension
1090 * @return Status\StatusInterface
1091 */
1092 protected function checkRequiredPhpExtension($extension) {
1093 if (!extension_loaded($extension)) {
1094 $status = new Status\ErrorStatus();
1095 $status->setTitle('PHP extension ' . $extension . ' not loaded');
1096 $status->setMessage(
1097 'TYPO3 CMS uses PHP extension ' . $extension . ' but it is not loaded' .
1098 ' in your environment. Change your environment to provide this extension.'
1099 );
1100 } else {
1101 $status = new Status\OkStatus();
1102 $status->setTitle('PHP extension ' . $extension . ' loaded');
1103 }
1104 return $status;
1105 }
1106
1107 /**
1108 * Check imagecreatetruecolor to verify gdlib works as expected
1109 *
1110 * @return Status\StatusInterface
1111 */
1112 protected function checkGdLibTrueColorSupport() {
1113 if (function_exists('imagecreatetruecolor')) {
1114 $imageResource = @imagecreatetruecolor(50, 100);
1115 if (is_resource($imageResource)) {
1116 imagedestroy($imageResource);
1117 $status = new Status\OkStatus();
1118 $status->setTitle('PHP GD library true color works');
1119 } else {
1120 $status = new Status\ErrorStatus();
1121 $status->setTitle('PHP GD library true color support broken');
1122 $status->setMessage(
1123 'GD is loaded, but calling imagecreatetruecolor() fails.' .
1124 ' This must be fixed, TYPO3 CMS won\'t work well otherwise.'
1125 );
1126 }
1127 } else {
1128 $status = new Status\ErrorStatus();
1129 $status->setTitle('PHP GD library true color support missing');
1130 $status->setMessage(
1131 'Gdlib is essential for TYPO3 CMS to work properly.'
1132 );
1133 }
1134 return $status;
1135 }
1136
1137 /**
1138 * Check gif support of GD library
1139 *
1140 * @return Status\StatusInterface
1141 */
1142 protected function checkGdLibGifSupport() {
1143 if (
1144 function_exists('imagecreatefromgif')
1145 && function_exists('imagegif')
1146 && (imagetypes() & IMG_GIF)
1147 ) {
1148 $imageResource = @imagecreatefromgif(__DIR__ . '/../../Resources/Public/Images/TestInput/Test.gif');
1149 if (is_resource($imageResource)) {
1150 imagedestroy($imageResource);
1151 $status = new Status\OkStatus();
1152 $status->setTitle('PHP GD library has gif support');
1153 } else {
1154 $status = new Status\ErrorStatus();
1155 $status->setTitle('PHP GD library gif support broken');
1156 $status->setMessage(
1157 'GD is loaded, but calling imagecreatefromgif() fails.' .
1158 ' This must be fixed, TYPO3 CMS won\'t work well otherwise.'
1159 );
1160 }
1161 } else {
1162 $status = new Status\ErrorStatus();
1163 $status->setTitle('PHP GD library gif support missing');
1164 $status->setMessage(
1165 'GD must be compiled with gif support. This is essential for' .
1166 ' TYPO3 CMS to work properly.'
1167 );
1168 }
1169 return $status;
1170 }
1171
1172 /**
1173 * Check jgp support of GD library
1174 *
1175 * @return Status\StatusInterface
1176 */
1177 protected function checkGdLibJpgSupport() {
1178 if (
1179 function_exists('imagecreatefromjpeg')
1180 && function_exists('imagejpeg')
1181 && (imagetypes() & IMG_JPG)
1182 ) {
1183 $status = new Status\OkStatus();
1184 $status->setTitle('PHP GD library has jpg support');
1185 } else {
1186 $status = new Status\ErrorStatus();
1187 $status->setTitle('PHP GD library jpg support missing');
1188 $status->setMessage(
1189 'GD must be compiled with jpg support. This is essential for' .
1190 ' TYPO3 CMS to work properly.'
1191 );
1192 }
1193 return $status;
1194 }
1195
1196 /**
1197 * Check png support of GD library
1198 *
1199 * @return Status\StatusInterface
1200 */
1201 protected function checkGdLibPngSupport() {
1202 if (
1203 function_exists('imagecreatefrompng')
1204 && function_exists('imagepng')
1205 && (imagetypes() & IMG_PNG)
1206 ) {
1207 $imageResource = @imagecreatefrompng(__DIR__ . '/../../Resources/Public/Images/TestInput/Test.png');
1208 if (is_resource($imageResource)) {
1209 imagedestroy($imageResource);
1210 $status = new Status\OkStatus();
1211 $status->setTitle('PHP GD library has png support');
1212 } else {
1213 $status = new Status\ErrorStatus();
1214 $status->setTitle('PHP GD library png support broken');
1215 $status->setMessage(
1216 'GD is compiled with png support, but calling imagecreatefrompng() fails.' .
1217 ' Check your environment and fix it, png in GD lib is important' .
1218 ' for TYPO3 CMS to work properly.'
1219 );
1220 }
1221 } else {
1222 $status = new Status\ErrorStatus();
1223 $status->setTitle('PHP GD library png support missing');
1224 $status->setMessage(
1225 'GD must be compiled with png support. This is essential for' .
1226 ' TYPO3 CMS to work properly'
1227 );
1228 }
1229 return $status;
1230 }
1231
1232 /**
1233 * Check gdlib supports freetype
1234 *
1235 * @return Status\StatusInterface
1236 */
1237 protected function checkGdLibFreeTypeSupport() {
1238 if (function_exists('imagettftext')) {
1239 $status = new Status\OkStatus();
1240 $status->setTitle('PHP GD library has freetype font support');
1241 $status->setMessage(
1242 'There is a difference between the font size setting which the GD' .
1243 ' library should be supplied with. If installation is completed' .
1244 ' a test in the install tool helps to find out the value you need.'
1245 );
1246 } else {
1247 $status = new Status\ErrorStatus();
1248 $status->setTitle('PHP GD library freetype support missing');
1249 $status->setMessage(
1250 'Some core functionality and extension rely on the GD' .
1251 ' to render fonts on images. This support is missing' .
1252 ' in your environment. Install it.'
1253 );
1254 }
1255 return $status;
1256 }
1257
1258 /**
1259 * Create true type font test image
1260 *
1261 * @return Status\StatusInterface
1262 */
1263 protected function isTrueTypeFontDpiStandard() {
1264 if (function_exists('imageftbbox')) {
1265 // 20 Pixels at 96 DPI - the DefaultConfiguration
1266 $fontSize = (20 / 96 * 72);
1267 $textDimensions = @imageftbbox(
1268 $fontSize,
1269 0,
1270 __DIR__ . '/../../Resources/Private/Font/vera.ttf',
1271 'Testing true type support'
1272 );
1273 $fontBoxWidth = $textDimensions[2] - $textDimensions[0];
1274 if ($fontBoxWidth < 300 && $fontBoxWidth > 200) {
1275 $status = new Status\OkStatus();
1276 $status->setTitle('FreeType True Type Font DPI');
1277 $status->setMessage('Fonts are rendered by FreeType library. ' .
1278 'We need to ensure that the final dimensions are as expected. ' .
1279 'This server renderes fonts based on 96 DPI correctly'
1280 );
1281 } else {
1282 $status = new Status\NoticeStatus();
1283 $status->setTitle('FreeType True Type Font DPI');
1284 $status->setMessage('Fonts are rendered by FreeType library. ' .
1285 'This server does not render fonts as expected. ' .
1286 'Please configure FreeType or TYPO3_CONF_VARS[GFX][TTFdpi]'
1287 );
1288 }
1289 } else {
1290 $status = new Status\ErrorStatus();
1291 $status->setTitle('PHP GD library freetype2 support missing');
1292 $status->setMessage(
1293 'The core relies on GD library compiled into PHP with freetype2' .
1294 ' support. This is missing on your system. Please install it.'
1295 );
1296 }
1297
1298 return $status;
1299 }
1300
1301 /**
1302 * Check php magic quotes
1303 *
1304 * @return Status\StatusInterface
1305 */
1306 protected function checkPhpMagicQuotes() {
1307 $magicQuotesGpc = get_magic_quotes_gpc();
1308 if ($magicQuotesGpc) {
1309 $status = new Status\WarningStatus();
1310 $status->setTitle('PHP magic quotes on');
1311 $status->setMessage(
1312 'magic_quotes_gpc=' . $magicQuotesGpc . LF .
1313 'Setting magic_quotes_gpc is deprecated since PHP 5.3.' .
1314 ' You are advised to disable it until it is completely removed:' . LF .
1315 'magic_quotes_gpc=Off'
1316 );
1317 } else {
1318 $status = new Status\OkStatus();
1319 $status->setTitle('PHP magic quotes off');
1320 }
1321 return $status;
1322 }
1323
1324 /**
1325 * Check register globals
1326 *
1327 * @return Status\StatusInterface
1328 */
1329 protected function checkRegisterGlobals() {
1330 $registerGlobalsEnabled = filter_var(
1331 ini_get('register_globals'),
1332 FILTER_VALIDATE_BOOLEAN,
1333 array(FILTER_REQUIRE_SCALAR, FILTER_NULL_ON_FAILURE)
1334 );
1335 if ($registerGlobalsEnabled === TRUE) {
1336 $status = new Status\ErrorStatus();
1337 $status->setTitle('PHP register globals on');
1338 $status->setMessage(
1339 'register_globals=' . ini_get('register_globals') . LF .
1340 'TYPO3 requires PHP setting "register_globals" set to off.' .
1341 ' This ancient PHP setting is a big security problem and should' .
1342 ' never be enabled:' . LF .
1343 'register_globals=Off'
1344 );
1345 } else {
1346 $status = new Status\OkStatus();
1347 $status->setTitle('PHP register globals off');
1348 }
1349 return $status;
1350 }
1351
1352 /**
1353 * Check for bug in libxml
1354 *
1355 * @return Status\StatusInterface
1356 */
1357 protected function checkLibXmlBug() {
1358 $sampleArray = array('Test>><<Data');
1359
1360 $xmlContent = '<numIndex index="0">Test&gt;&gt;&lt;&lt;Data</numIndex>' . LF;
1361
1362 $xml = \TYPO3\CMS\Core\Utility\GeneralUtility::array2xml($sampleArray, '', -1);
1363
1364 if ($xmlContent !== $xml) {
1365 $status = new Status\ErrorStatus();
1366 $status->setTitle('PHP libxml bug present');
1367 $status->setMessage(
1368 'Some hosts have problems saving ">><<" in a flexform.' .
1369 ' To fix this, enable [BE][flexformForceCDATA] in' .
1370 ' All Configuration.'
1371 );
1372 } else {
1373 $status = new Status\OkStatus();
1374 $status->setTitle('PHP libxml bug not present');
1375 }
1376 return $status;
1377 }
1378
1379 /**
1380 * Helper methods
1381 */
1382
1383 /**
1384 * Validate a given IP address.
1385 *
1386 * @param string $ip IP address to be tested
1387 * @return boolean
1388 */
1389 protected function isValidIp($ip) {
1390 return filter_var($ip, FILTER_VALIDATE_IP) !== FALSE;
1391 }
1392
1393 /**
1394 * Test if this instance runs on windows OS
1395 *
1396 * @return boolean TRUE if operating system is windows
1397 */
1398 protected function isWindowsOs() {
1399 $windowsOs = FALSE;
1400 if (!stristr(PHP_OS, 'darwin') && stristr(PHP_OS, 'win')) {
1401 $windowsOs = TRUE;
1402 }
1403 return $windowsOs;
1404 }
1405
1406 /**
1407 * Helper method to find out if suhosin extension is loaded
1408 *
1409 * @return boolean TRUE if suhosin PHP extension is loaded
1410 */
1411 protected function isSuhosinLoadedAndActive() {
1412 $suhosinLoaded = FALSE;
1413 if (extension_loaded('suhosin')) {
1414 $suhosinInSimulationMode = filter_var(
1415 ini_get('suhosin.simulation'),
1416 FILTER_VALIDATE_BOOLEAN,
1417 array(FILTER_REQUIRE_SCALAR, FILTER_NULL_ON_FAILURE)
1418 );
1419 if (!$suhosinInSimulationMode) {
1420 $suhosinLoaded = TRUE;
1421 }
1422 }
1423 return $suhosinLoaded;
1424 }
1425
1426 /**
1427 * Helper method to explode a string by delimeter and throw away empty values.
1428 * Removes empty values from result array.
1429 *
1430 * @param string $delimiter Delimiter string to explode with
1431 * @param string $string The string to explode
1432 * @return array Exploded values
1433 */
1434 protected function trimExplode($delimiter, $string) {
1435 $explodedValues = explode($delimiter, $string);
1436 $resultWithPossibleEmptyValues = array_map('trim', $explodedValues);
1437 $result = array();
1438 foreach ($resultWithPossibleEmptyValues as $value) {
1439 if ($value !== '') {
1440 $result[] = $value;
1441 }
1442 }
1443 return $result;
1444 }
1445
1446 /**
1447 * Helper method to get the bytes value from a measurement string like "100k".
1448 *
1449 * @param string $measurement The measurement (e.g. "100k")
1450 * @return integer The bytes value (e.g. 102400)
1451 */
1452 protected function getBytesFromSizeMeasurement($measurement) {
1453 $bytes = doubleval($measurement);
1454 if (stripos($measurement, 'G')) {
1455 $bytes *= 1024 * 1024 * 1024;
1456 } elseif (stripos($measurement, 'M')) {
1457 $bytes *= 1024 * 1024;
1458 } elseif (stripos($measurement, 'K')) {
1459 $bytes *= 1024;
1460 }
1461 return (int)$bytes;
1462 }
1463 }