Bug #17592: safe mode doesn't work as described in the manual

From: Date: Tue, 04 Jun 2002 10:17:29 +0000
Subject: Bug #17592: safe mode doesn't work as described in the manual
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-9443@lists.php.net to get a copy of this message
From: fontajos@phpeppershop.org Operating system: SuSE Linux 7.1 Professional PHP version: 4.1.2 PHP Bug Type: *Configuration Issues Bug description: safe mode doesn't work as described in the manual In the php manual (http://www.php.net/manual/en/features.safe-mode.php) the safe mode is described as follows. PHP should compare the UID of the script's owner to the UID of the file on which the script attends to operate. If the UIDs differ, the access to the file is denied. If you test the following script, assuming you have a file called text.txt (file and directory properties not 0666!) in the same directory where the script is, it should work according to the php manuals description, but it doesn't. (You can execute the following script on our server, to see exactly the same result that I got here: http://phpserver.zhwin.ch/~fontajos/test/test2.php ) ------------- <?php echo("<h1>Safe Mode bug</h1><br><br>");//title clearstatcache(); echo ("<u>Script</u><br>"); echo ("This script's UID = ".getmyuid()." and GID = ".getmygid()."<br>"); echo ("The current user of this script is: ".get_current_user()."<br><br>"); echo ("<u>File</u><br>"); echo ("./text.txt's UID = ".fileowner("text.txt")."<br>"); $posix_array = posix_getpwuid(fileowner("text.txt")); echo ("./text.txt's owner = ".$posix_array['name']."<br>"); //Some more fileinfos if (file_exists("text.txt")) { echo ("File text.txt exists in this folder!<br>"); } if (is_readable("text.txt")) { echo ("File text.txt is readable!<br>"); } if (is_writeable("text.txt")) { echo("File text.txt is writeable!<br><br>"); } else { echo ("File text.txt is <b>not writeable</b>!<br><br>"); } /*Try an operation which does not work although it should*/ chmod ("text.txt", 0666); $fp = fopen ("text.txt", "r+"); fclose($fp); chmod ("text.txt", 0644); ?> -------------- To reproduce this behaviour, I used the following PHP configuration: http://phpserver.zhwin.ch/~fontajos/phpinfo.php Since most of the providers enable the Safe Mode, it is really annoying that we currently need to give the directory and the specific file the file attributes 0666 to access them with enabled Safe Mode. Best Regards Jose Fontanil -- Edit bug report at http://bugs.php.net/?id=17592&edit=1 -- Fixed in CVS: http://bugs.php.net/fix.php?id=17592&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=17592&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=17592&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=17592&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=17592&r=support Expected behavior: http://bugs.php.net/fix.php?id=17592&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=17592&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=17592&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=17592&r=globals

« previous php.bugs (#9443) next »