Bug #17592: safe mode doesn't work as described in the manual
| From: | fontajos at phpeppershop dot org | Date: | Tue, 04 Jun 2002 10:17:29 +0000 |
| Subject: | Bug #17592: safe mode doesn't work as described in the manual | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-9443@lists.php.net to get a copy of this message | ||
From: fontajos@phpeppershop.org
Operating system: SuSE Linux 7.1 Professional
PHP version: 4.1.2
PHP Bug Type: *Configuration Issues
Bug description: safe mode doesn't work as described in the manual
In the php manual (http://www.php.net/manual/en/features.safe-mode.php) the
safe mode is described as follows. PHP should compare the UID of the
script's owner to the UID of the file on which the script attends to
operate. If the UIDs differ, the access to the file is denied.
If you test the following script, assuming you have a file called text.txt
(file and directory properties not 0666!) in the same directory where the
script is, it should work according to the php manuals description, but it
doesn't. (You can execute the following script on our server, to see
exactly the same result that I got here:
http://phpserver.zhwin.ch/~fontajos/test/test2.php
)
-------------
<?php
echo("<h1>Safe Mode bug</h1><br><br>");//title
clearstatcache();
echo ("<u>Script</u><br>");
echo ("This script's UID = ".getmyuid()." and GID =
".getmygid()."<br>");
echo ("The current user of this script is:
".get_current_user()."<br><br>");
echo ("<u>File</u><br>");
echo ("./text.txt's UID = ".fileowner("text.txt")."<br>");
$posix_array = posix_getpwuid(fileowner("text.txt"));
echo ("./text.txt's owner = ".$posix_array['name']."<br>");
//Some more fileinfos
if (file_exists("text.txt")) {
echo ("File text.txt exists in this folder!<br>");
}
if (is_readable("text.txt")) {
echo ("File text.txt is readable!<br>");
}
if (is_writeable("text.txt")) {
echo("File text.txt is writeable!<br><br>");
} else {
echo ("File text.txt is <b>not writeable</b>!<br><br>");
}
/*Try an operation which does not work although it should*/
chmod ("text.txt", 0666);
$fp = fopen ("text.txt", "r+");
fclose($fp);
chmod ("text.txt", 0644);
?>
--------------
To reproduce this behaviour, I used the following PHP configuration:
http://phpserver.zhwin.ch/~fontajos/phpinfo.php
Since most of the providers enable the Safe Mode, it is really annoying
that we currently need to give the directory and the specific file the
file attributes 0666 to access them with enabled Safe Mode.
Best Regards
Jose Fontanil
--
Edit bug report at http://bugs.php.net/?id=17592&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=17592&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=17592&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=17592&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=17592&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=17592&r=support
Expected behavior: http://bugs.php.net/fix.php?id=17592&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=17592&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=17592&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=17592&r=globals