#23696 [NEW]: safe_mode uid test in apache chroot
| From: | veins at skreel dot org | Date: | Mon, 19 May 2003 13:05:59 +0000 |
| Subject: | #23696 [NEW]: safe_mode uid test in apache chroot | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-39948@lists.php.net to get a copy of this message | ||
From: veins at skreel dot org
Operating system: Unix
PHP version: 4.3.1
PHP Bug Type: *General Issues
Bug description: safe_mode uid test in apache chroot
I am running apache in a chroot() and figured out yesterday that it breaks
the uid checks in safe mode.
From what i understood, php *emulates* setuid scripts by checking
ownership of a file before accessing it from another. This could
theoritically be done by calling stat() on the file and checking the
st_uid field but for some reason, it appears that if the user database is
not in the chroot, php will fail the checks, to be more precise, the check
will always appear to be valid (i suspect this from being the result of a
comparison between two error values).
This means that:
<?
include('someonesfile'); // will succeed
echo getmyuid(); // the uid of owner of file
// not from apache's child
?>
since getmyuid() shows me the uid of owner of file, then it proves me that
uid of owner of file is successfully detected (stat() ?) and since
include() succeeds (unless i start copying all the user and group files in
chroot) despite the fact that the owner of 'someonesfile' is not equal to
value of getmyuid(), it makes me think that a getpw*() function call is
being used for some reason that I couldnt figure out yet.
I didnt get a chance yet to look deep inside the source code since im ill,
so the reasons of why this happens are plain suppositions but the problems
occurs. Im sorry if I am not clear, mail me and I try explain in a more
clear way. I will try to get some free time this week to figure this out
since its quite annoying but maybe a developper could explain brievely how
the checks are done ?
--
Edit bug report at http://bugs.php.net/?id=23696&edit=1
--
Try a CVS snapshot: http://bugs.php.net/fix.php?id=23696&r=trysnapshot
Fixed in CVS: http://bugs.php.net/fix.php?id=23696&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=23696&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=23696&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=23696&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=23696&r=support
Expected behavior: http://bugs.php.net/fix.php?id=23696&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=23696&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=23696&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=23696&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=23696&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=23696&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=23696&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=23696&r=gnused