#36551 [NEW]: Improve safe_mode file upload compatibility
| From: | nanovox at gmail dot com | Date: | Mon, 27 Feb 2006 20:41:24 +0000 |
| Subject: | #36551 [NEW]: Improve safe_mode file upload compatibility | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-93733@lists.php.net to get a copy of this message | ||
From: nanovox at gmail dot com
Operating system: Fedora Core 4/Linux 2.6.14.3
PHP version: 5.1.2
PHP Bug Type: Feature/Change Request
Bug description: Improve safe_mode file upload compatibility
Description:
------------
Currently the function, move_uploaded_file, works in safe mode, but does
not behave as I believe it should. Neither does the upload_tmp_dir ini
system variable.
As you know PHP runs with the apache permissions. The problem comes with
safe_mode. When the script limits the use of files based on their group
and ownership settings, it causes some problems when you're uploading
files. This is because all files created during an upload are given the
apache permissions instead of the script's permissions.
Another problem is that the upload_tmp_dir variable doesn't work in safe
mode. I've set it to /shared/tmp but php still uses /tmp instead.
I prepose that in php safe_mode, the upload_tmp_dir should be settable
(using php_admin_value options in the apache config). Then all temporary
upload files should be created with the group and ownership of the
temporary folder. Thus if your upload_tmp_dir folder is owned by
johndoe:webgroup the temporary files should also have the same ownership.
As long as the openbase_dir allows access to the temporary directory and
the siteroot, move_uploaded_file should be able to transfer files between
the two spots and the ownership would remain as that of the script that
was run.
I believe this would eliminate the largest problem of safe mode without
compromising security. It would at least save people in a shared
environment from the consequences of an open source php program that has
to run outside of safe_mode for such reasons.
Without these measures, a php script could not allow you to upload a file
and limit access based on the php application's restrictions. Namely,
upload a copyrighted image and only provide access to that image for those
who have purchased the image without turning off safe mode and opening up
your whole computer to obvious security risks.
Reproduce code:
---------------
- set: php_admin_value safe_mode 1
- set: php_admin_value upload_tmp_dir "/home/johndoe/webtmp"
- upload file using a form (upload to the upload_tmp_dir)
- move_uploaded_file from /home/johndoe/webtmp to other location found in
openbase_dir value
- try opening the uploaded file with a php script that has different
ownership than that of apache web server.
Expected result:
----------------
File should save to upload_tmp_dir and have ownership of the tmp_dir's
folder, even in safe_mode. After moving it, the script should be openable
in a php script because the uploaded file should have the same permissions
as that of the running script.
Actual result:
--------------
upload_tmp_dir is ignored and file is placed in /tmp folder with owner and
group being the same as what the apache web server is running as. moving
the file to johndoe's web directory leaves the ownership as being apache's
ownership. Scripts that use the file can't because they are running with
johndoe's permissions while the file is using apache's permissions.
--
Edit bug report at http://bugs.php.net/?id=36551&edit=1
--
Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=36551&r=trysnapshot44
Try a CVS snapshot (PHP 5.1): http://bugs.php.net/fix.php?id=36551&r=trysnapshot51
Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=36551&r=trysnapshot60
Fixed in CVS: http://bugs.php.net/fix.php?id=36551&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=36551&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=36551&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=36551&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=36551&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=36551&r=support
Expected behavior: http://bugs.php.net/fix.php?id=36551&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=36551&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=36551&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=36551&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=36551&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=36551&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=36551&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=36551&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=36551&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=36551&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=36551&r=mysqlcfg