Change record status: 
Project: 
Introduced in branch: 
7.x
Introduced in version: 
7.103
Description: 

The previous behavior for displaying errors in Drupal 7 was to display full path of the affected file (including DRUPAL_ROOT path). This has security implications.

Original error message example:

Warning: file_get_contents(/x.txt): Failed to open stream: No such file or directory in include_once() (line 312 of /var/www/test/sites/default/settings.php).

After this change, all displayed errors have now the DRUPAL_ROOT path stripped from the full path. Only the relative path to the Drupal root directory will be displayed.

New error message example:

Warning: file_get_contents(/x.txt): Failed to open stream: No such file or directory in include_once() (line 312 of sites/default/settings.php).
Impacts: 
Site builders, administrators, editors
Module developers
Site templates, recipes and distribution developers