Bug #17466 Updated: Safe mode uid -1 bug

From: Date: Thu, 20 Jun 2002 19:14:06 +0000
Subject: Bug #17466 Updated: Safe mode uid -1 bug
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-11602@lists.php.net to get a copy of this message
ID: 17466 Updated by: brian@brian-web.com Reported By: cjones@dualboot.net Status: Open Bug Type: Apache2 related Operating System: Linux 2.4.7-10 PHP Version: 4.2.1 New Comment: That patch I just posted is broken with Apache 2.0.39, apparently the finfo struct isn't filled in 2.0.39 at the point that I was accessing it. (Its all 0s). If you move the call to php_apr_finfo2stat to php_apache_get_stat it works, but then its runs everytime php_apache_get_stat is called, which I was trying to avoid. Previous Comments: ------------------------------------------------------------------------ [2002-06-20 03:07:29] brian@brian-web.com I hit the same problem too with apache 2.0.36/php 4.2.1. I figured out where the problem was and fixed it. The apache2filter sapi module wasn't implementing a get_stat function. You can grab the patch from: http://www.brian-web.com/misc/apache2-php-safemode.patch I'm not too familiar with the Apache2 or PHP source, so someone else should probably take a look at it. Basically, it takes the apr_finfo_t struct from apache and converts it back to a struct stat for php. ------------------------------------------------------------------------ [2002-05-28 02:24:18] derick@php.net reclassify as an apache 2 issue ------------------------------------------------------------------------ [2002-05-28 01:15:24] cjones@dualboot.net Update. I installed the CVS release (4.3.0-dev) and the problem still exists there. I switched over to the CGI/commandline install of PHP (4.2.1) and it works correctly (i.e. when safe_mode is on it gets the correct uid of the file owner). ------------------------------------------------------------------------ [2002-05-27 20:53:17] cjones@dualboot.net Little bit of extra info (which may or may not be helpful), OS version: Linux version 2.4.7-10smp (bhcompile@stripples.devel.redhat.com) (gcc version 2.96 20000731 (Red Hat Linux 7.1 2.96-98)) #1 SMP Thu Sep 6 17:09:31 EDT 2001 Apache config commands: ./configure --prefix=/usr/local/apache --enable-so --enable-rewrite=shared --enable-ssl=shared --enable-suxec=shared PHP config commands: ./configure --with-mysql=/usr/local/mysql --with-apxs2=/usr/local/apache/bin/apxs ------------------------------------------------------------------------ [2002-05-27 20:45:19] cjones@dualboot.net When safe mode is on php is unable to determine the uid of the running script, it reports it as -1. As you might imagine, this completely breaks the utility of safe mode with respect to file access. Also, the same bug occurs when using safe_mode_gid (it reports the gid as -1 as well). Note that it does get the appropriate uid/gid for the file that is attempted to be accessed. I am running Apache 2.0.36 and the newest version of PHP (4.2.1). I did some poking around and I think I found out what's going on. In ext/standard/pageinfo.c, php_statpage() tries to determine and stat the running script file like so: -------------------------------------------- pstat = sapi_get_stat(TSRMLS_C); if (BG(page_uid)==-1 || BG(page_gid)==-1) { if(pstat) { BG(page_uid) = pstat->st_uid; BG(page_gid) = pstat->st_gid; BG(page_inode) = pstat->st_ino; BG(page_mtime) = pstat->st_mtime; } } -------------------------------------------- pstat is not properly set by sapi_get_stat() (from main/SAPI.c) so the page_uid et al values are not changed, and retain their defaults (-1). I looked around a bit to see if I could make a workaround by stating the script file without using sapi_get_stat but I couldn't figure out what variable contained the script filename. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17466&edit=1

« previous php.bugs (#11602) next »