Bug #17858 Updated: Apache 2 and PHP 4 breaks safe_mode

From: Date: Fri, 19 Jul 2002 03:54:36 +0000
Subject: Bug #17858 Updated: Apache 2 and PHP 4 breaks safe_mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14580@lists.php.net to get a copy of this message
ID: 17858 Updated by: slamb@slamb.org Reported By: moron@industrial.org Status: Open Bug Type: Apache2 related Operating System: Linux PHP Version: 4.3.0-dev New Comment: I've got a patch now that "fixes" this. <http://www.slamb.org/php-apache2-safemode.patch> It makes a stat(2) system call that isn't strictly necessary - rec->finfo has this information, but not in the struct stat form. It will probably put a lot of stuff in your error log if you try serve things that aren't files, which Apache2 is capable of. (I.e., coming from a Subversion repository.) Previous Comments: ------------------------------------------------------------------------ [2002-07-18 23:09:39] slamb@slamb.org sniper, if this was fixed, I think it has regressed. I have the same problem with CVS pulled like 30 minutes ago. Victor, could you post a context diff of what you did? I took a quick look at the file/lines you mentioned, but I think those line numbers are no longer correct. ------------------------------------------------------------------------ [2002-07-09 10:53:08] roel@oms-net.nl Got newest version today (http://snaps.php.net/php4-latest.tar.gz) DD: 20020809 @ approx. 15.00 CET. Using this version I still have the same problem. ------------------------------------------------------------------------ [2002-06-28 03:56:44] sniper@php.net forgot to update version. ------------------------------------------------------------------------ [2002-06-20 01:18:50] moron@industrial.org Actually, the latest snapshot makes things worse in a way. To get it to install you need to turn off SAFE_MODE due to something with the PEAR section that creates a chicken and the egg scenario: make[1]: Entering directory `/usr/local/source/php4-200206192100' /usr/local/source/php4-200206192100/sapi/cli/php /usr/local/source/php4-200206192100/pear/install-pear.php /usr/local/source/php4-200206192100/pear/package-*.xml Warning: SAFE MODE Restriction in effect. The script whose uid is -1 is not allowed to access /usr/local/source/php4-200206192100/pear/PEAR.php owned by uid 100 in /usr/local/source/php4-200206192100/pear/install-pear.php on line 6 After turning off safe_mode and open_basedir temporarily, I managed to complete an install but then got a new error along with the old ones: SAFE MODE Restriction in effect. The script whose uid is -1 is not allowed to access /home/httpd/html/test.php owned by uid 0 in Unknown on line 0 Warning: (null)("/home/httpd/html/test.php") - Resource temporarily unavailable in Unknown on line 0 Warning: Failed opening '/home/httpd/html/test.php' for inclusion (include_path='.:/usr/local/lib/php') in Unknown on line 0 So this does appear to still be FUBAR in the current distribution. The "Resource temporarily unavailable" is a new error just so you know. Cheers ------------------------------------------------------------------------ [2002-06-20 00:09:04] sniper@php.net AFAIK this is already fixed in CVS. Try this snapshot: http://snaps.php.net/php4-latest.tar.gz ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/17858 -- Edit this bug report at http://bugs.php.net/?id=17858&edit=1

« previous php.bugs (#14580) next »