#31618 [Fbk]: is_readable() results based on ownership of calling script, not file
From: tony2001@php.net Date: Wed, 10 Aug 2005 18:44:06 +0000 Subject: #31618 [Fbk]: is_readable() results based on ownership of calling script, not file References: 1 Groups: php.bugs Request: Send a blank email to php-bugs+get-83341@lists.php.net to get a copy of this message
ID: 31618
Updated by: tony2001@php.net
Reported By: kibab at icehouse dot net
Status: Feedback
Bug Type: Filesystem function related
Operating System: redhat enterprise
PHP Version: 5CVS-2005-03-14
New Comment:
Of course, I meant this:
<?php
$myfilename = '/usr/share/pear/commonfile.php';
fopen($myfilename, 'r');
?>
Previous Comments:
------------------------------------------------------------------------
[2005-08-10 20:36:39] tony2001@php.net
Could you plz also try this:
<?php
fopen($myfilename, 'r');
?>
And post the error message here.
Thanks.
------------------------------------------------------------------------
[2005-08-10 20:24:48] kibab at icehouse dot net
Ok, here's a new "complete" example for you.
First, we need to do some setup as this is based on
permissions, ownership, and safe mode:
cd <some directory in safe_mode_include_dir>
# note, I used cd /usr/share/pear
echo "TESTING" > commonfile.php
chmod a+r commonfile.php
Then: $ ls -l commonfile*
-rw-rw-r-- 1 root root 8 Aug 10 10:54
commonfile.php
And, permissions on the source PHP file in use:
$ ls -l bug31618.php
-rw-rw-r-- 1 kpederson financialaid 576 Aug 10
10:50 bug31618.php
I used the following relevant settings:
$ grep -iE "safe|include" /etc/php.ini | grep -v "^;"
safe_mode = On
safe_mode_gid = On
safe_mode_include_dir = /usr/share/pear
safe_mode_exec_dir = "/usr/local/php_exe/bin"
safe_mode_allowed_env_vars = PHP_
safe_mode_protected_env_vars = LD_LIBRARY_PATH
include_path =
".:/usr/share/pear/:/usr/share/pear/ewu_lib:/var/lib/php_secure"
sql.safe_mode = Off
Now, grab my PHP script from the following URL:
http://www.ewu.edu/web/tools/bug31618.php.txt
It's output looks like the following (as can be seen from
http://www.ewu.edu/web/tools/bug31618.php):
is_readable: /usr/share/pear/commonfile.php (false)
TESTING
Now, if I change the ownership to root:root (as I did for
bug31618_2.php, eg. as seen by
http://www.ewu.edu/web/tools/bug31618_2.php):
is_readable: /usr/share/pear/commonfile.php (true)
TESTING
Thus, the results are based on ownership of the calling
php script, not the file attempting to be read, despite
being in safe_mode_include_dir.
------------------------------------------------------------------------
[2005-08-08 19:56:08] sniper@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc.
If possible, make the script source available online and provide
an URL to it here. Try to avoid embedding huge scripts into the report.
------------------------------------------------------------------------
[2005-05-19 06:14:33] kibab at icehouse dot net
From memory, all files were mode 664 and all directories
had permissions of 775 being owned by root:root. However,
I no longer have that same structure to prove that. If
you like, I can setup an almost identical test case using
the code that I included below (but using my new
structure).
------------------------------------------------------------------------
[2005-05-17 17:18:48] sniper@php.net
What are the permissions of all the directories in that path?
(/var/lib/php_packages/)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/31618
--
Edit this bug report at http://bugs.php.net/?id=31618&edit=1
Thread (38 messages)
- #31618 [Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Fbk->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Fbk]: is_readable() results based on ownership of calling script, not file
- #31618 [Fbk->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Fbk->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Fbk]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Fbk]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Fbk]: is_readable() results based on ownership of calling script, not file
- #31618 [Fbk->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Com]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Asn]: is_readable() results based on ownership of calling script, not file
- #31618 [Asn->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Asn]: is_readable() results based on ownership of calling script, not file
- #31618 [Asn->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Fbk]: is_readable() results based on ownership of calling script, not file
- #31618 [Fbk->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Fbk]: is_readable() results based on ownership of calling script, not file
- #31618 [Fbk]: is_readable() results based on ownership of calling script, not file
- #31618 [Fbk->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Bgs]: is_readable() results based on ownership of calling script, not file
- #31618 [Bgs->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Fbk]: is_readable() results based on ownership of calling script, not file
- #31618 [Fbk->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Fbk]: is_readable() results based on ownership of calling script, not file
- #31618 [Fbk->Opn]: is_readable() results based on ownership of calling script, not file
- #31618 [Opn->Asn]: is_readable() results based on ownership of calling script, not file
- #31618 [Asn]: is_readable() results based on ownership of calling script, not file
- #31618 [Asn]: is_readable() results based on ownership of calling script, not file
- #31618 [Asn]: is_readable() results based on ownership of calling script, not file
- #31618 [Com]: is_readable() results based on ownership of calling script, not file
- #31618 [Com]: is_readable() results based on ownership of calling script, not file
- #31618 [Com]: is_readable() results based on ownership of calling script, not file
- #31618 [Asn]: is_readable() results based on ownership of calling script, not file
- #31618 [Com]: is_readable() results based on ownership of calling script, not file
- #31618 [Asn->Sus]: is_readable() results based on ownership of calling script, not file
| « previous | php.bugs (#83341) | next » |
|---|