#23696 [Opn]: safe_mode uid test in apache chroot
| From: | veins at skreel dot org | Date: | Thu, 22 May 2003 14:19:00 +0000 |
| Subject: | #23696 [Opn]: safe_mode uid test in apache chroot | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-40195@lists.php.net to get a copy of this message | ||
ID: 23696
User updated by: veins at skreel dot org
Reported By: veins at skreel dot org
Status: Open
Bug Type: *General Issues
Operating System: Unix
PHP Version: 4.3.1
New Comment:
i have played a bit with this issue and figured out the following:
still in my chrooted environement:
<? include("./file"); ?> triggers the safe_mode error
<? include("file"); ?> works when it should not
i am currently reading the sources but need some time to understand a
few things (lots of weird macros, lots of strange functions, and what
files do what) :)
any help in fixing this issue will be greatly appreciated
Previous Comments:
------------------------------------------------------------------------
[2003-05-19 08:05:59] veins at skreel dot org
I am running apache in a chroot() and figured out yesterday that it
breaks the uid checks in safe mode.
From what i understood, php *emulates* setuid scripts by checking
ownership of a file before accessing it from another. This could
theoritically be done by calling stat() on the file and checking the
st_uid field but for some reason, it appears that if the user database
is not in the chroot, php will fail the checks, to be more precise, the
check will always appear to be valid (i suspect this from being the
result of a comparison between two error values).
This means that:
<?
include('someonesfile'); // will succeed
echo getmyuid(); // the uid of owner of file
// not from apache's child
?>
since getmyuid() shows me the uid of owner of file, then it proves me
that uid of owner of file is successfully detected (stat() ?) and since
include() succeeds (unless i start copying all the user and group files
in chroot) despite the fact that the owner of 'someonesfile' is not
equal to value of getmyuid(), it makes me think that a getpw*()
function call is being used for some reason that I couldnt figure out
yet.
I didnt get a chance yet to look deep inside the source code since im
ill, so the reasons of why this happens are plain suppositions but the
problems occurs. Im sorry if I am not clear, mail me and I try explain
in a more clear way. I will try to get some free time this week to
figure this out since its quite annoying but maybe a developper could
explain brievely how the checks are done ?
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23696&edit=1