Req #65935 [Opn->Sus]: support for checking script uid/gid

From: Date: Wed, 17 Nov 2021 18:36:47 +0000
Subject: Req #65935 [Opn->Sus]: support for checking script uid/gid
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237828@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65935&edit=1 ID: 65935 Updated by: cmb@php.net Reported by: mustnotbevalid at example dot com Summary: support for checking script uid/gid -Status: Open +Status: Suspended Type: Feature/Change Request Package: FPM related Operating System: Linux PHP Version: 5.4.21 Block user comment: N Private report: N New Comment: From a quick glance, that reminds me of safe_mode. Anyhow, this feature would require an RFC, so all details could be sufficiently discussed and clarified. Anybody is welcome to pursue the RFC process[1]; for the time being, I suspend this ticket. [1] <https://wiki.php.net/rfc/howto> Previous Comments: ------------------------------------------------------------------------ [2013-10-21 09:15:05] mustnotbevalid at example dot com Description: ------------ For security reasons, it would be nice to have the option similar to Apache suExec where FPM checks the uid/gid of the script file before executing it, and only allowing scripts to be executed with a matching uid/gid specified in the pool config file. This would serve as an extra layer of defense against exploit attempts which try to write files via PHP or other CGI scripts as they would be saved with the uid of the webserver. Combined with verbose logging of such requests, this would also serve as an a good indicator that some scripts on the system are insecure. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=65935&edit=1

« previous php.bugs (#237828) next »