Bug #17858: Apache 2 and PHP 4 breaks safe_mode
| From: | moron at industrial dot org | Date: | Thu, 20 Jun 2002 04:04:09 +0000 |
| Subject: | Bug #17858: Apache 2 and PHP 4 breaks safe_mode | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-11483@lists.php.net to get a copy of this message | ||
From: moron@industrial.org
Operating system: Linux
PHP version: 4.2.1
PHP Bug Type: Scripting Engine problem
Bug description: Apache 2 and PHP 4 breaks safe_mode
There is a problem with PHP 4 and Apache 2.0 relating to checking of the
UID and GID of scripts under safe_mode. The net result is that under
safe_mode, all scripts fail.
Here is an example error:
SAFE MODE Restriction in effect. The script whose uid is -1 is not allowed
to access /home/httpd/html/test.php owned by uid 0 in Unknown on line 0
Note that this is not for an include but the script itself. Also note the
bogus UID.
Here is a detailed description from another fellow I came across when
researching this via Google which quite eloquently explains the problem:
From: Victor Fernandes (Victor.Fernandes@comnet.be)
Subject: Re: [PHP-INST] PHP 4.x and Apache 2.x
Newsgroups: php.install
Date: 2002-06-18 04:19:11 PST
Just for the records and to give some hope ;-)
I found where the problem is and patched the sources to fix the problem
for me.
I will not suggest or recommend my solution (patch) because this should be
solved when PHP 4 will be fully supported with Apache 2.x. Yes I had this
error certainly due to this combination (Apache 2.0.36 and PHP 4.2.1,
Solaris 8, etc...)
On file "./sapi/apache2filter/apache_config.c" changed the string
"OR_NONE" on line 131, to "ACCESS_CONF|RSRC_CONF". Based on line 866 of
file: "./sapi/apache/mod_php4.c"
After that I was presented with a new nice error:
Warning: SAFE MODE Restriction in effect. The script whose uid/gid is
-1/-1 is not allowed..."
For any file I was trying to access. This again is certainly due to the
fact that this is experimental code for Apache 2.x. I found where the
problem is and patched the sources too.
For the curious and in case this is not yet known, the problem originates
on the "./main/safe_mode.c" file, because the php_getuid() and
php_getgid() functions always return -1. In fact the problem comes, even
more deeply, from the php_statpage() or sapi_get_stat(). I decided not
to go further and patched the php_getuid() and php_getgid() directly (on
file "./ext/standard/pageinfo.c"). I've done this by checking the value
that is supposed to be returned and if it is -1 go another way and get the
correct executing script uid/gid.
Victor Fernandes
--
Edit bug report at http://bugs.php.net/?id=17858&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=17858&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=17858&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=17858&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=17858&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=17858&r=support
Expected behavior: http://bugs.php.net/fix.php?id=17858&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=17858&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=17858&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=17858&r=globals