Bug #17592 Updated: safe mode doesn't work as described in the manual

From: Date: Wed, 05 Jun 2002 05:20:22 +0000
Subject: Bug #17592 Updated: safe mode doesn't work as described in the manual
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-9515@lists.php.net to get a copy of this message
ID: 17592 Updated by: fontajos@phpeppershop.org Reported By: fontajos@phpeppershop.org Status: Open Bug Type: *Configuration Issues Operating System: SuSE Linux 7.1 Professional PHP Version: 4.1.2 New Comment: ...sorry, that was the submit button, a little bit too fast ;-). You can run the above mentioned script here:http://phpserver.zhwin.ch/~fontajos/test/test2.php the comparison is entitled as fileownershop comparison, at the very bottom. Previous Comments: ------------------------------------------------------------------------ [2002-06-05 01:09:07] fontajos@phpeppershop.org Thank you for the quick reply. You write, that PHP does the following comparison: fileowner(\"test2.php\") == fileowner(\"text.txt\"); I tried this within a new script and both, the test2.php and also the text.txt do have the same UID. Test: <?php echo (fileowner("test3.php")." = ".fileowner("text.txt")); ?> (You can run this script here: But still it isn't possible to write to this file or use chmod as mentioned in the php manual (http://www.php.net/manual/en/features.safe-mode.php). ------------------------------------------------------------------------ [2002-06-04 07:43:04] steffann@php.net Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php You are comparing the user who *runs* the script (as returned by getmyuid()) with the owner of file.txt. Safe mode protection works not by looking at who runs the script, but by looking at who *owns* the script (as returned by fileowner(\"test2.php\")). To give access to the file, safe mode checks for: fileowner(\"test2.php\") == fileowner(\"text.txt\") ------------------------------------------------------------------------ [2002-06-04 06:17:28] fontajos@phpeppershop.org In the php manual (http://www.php.net/manual/en/features.safe-mode.php) the safe mode is described as follows. PHP should compare the UID of the script's owner to the UID of the file on which the script attends to operate. If the UIDs differ, the access to the file is denied. If you test the following script, assuming you have a file called text.txt (file and directory properties not 0666!) in the same directory where the script is, it should work according to the php manuals description, but it doesn't. (You can execute the following script on our server, to see exactly the same result that I got here: http://phpserver.zhwin.ch/~fontajos/test/test2.php ) ------------- <?php echo("<h1>Safe Mode bug</h1><br><br>");//title clearstatcache(); echo ("<u>Script</u><br>"); echo ("This script's UID = ".getmyuid()." and GID = ".getmygid()."<br>"); echo ("The current user of this script is: ".get_current_user()."<br><br>"); echo ("<u>File</u><br>"); echo ("./text.txt's UID = ".fileowner("text.txt")."<br>"); $posix_array = posix_getpwuid(fileowner("text.txt")); echo ("./text.txt's owner = ".$posix_array['name']."<br>"); //Some more fileinfos if (file_exists("text.txt")) { echo ("File text.txt exists in this folder!<br>"); } if (is_readable("text.txt")) { echo ("File text.txt is readable!<br>"); } if (is_writeable("text.txt")) { echo("File text.txt is writeable!<br><br>"); } else { echo ("File text.txt is <b>not writeable</b>!<br><br>"); } /*Try an operation which does not work although it should*/ chmod ("text.txt", 0666); $fp = fopen ("text.txt", "r+"); fclose($fp); chmod ("text.txt", 0644); ?> -------------- To reproduce this behaviour, I used the following PHP configuration: http://phpserver.zhwin.ch/~fontajos/phpinfo.php Since most of the providers enable the Safe Mode, it is really annoying that we currently need to give the directory and the specific file the file attributes 0666 to access them with enabled Safe Mode. Best Regards Jose Fontanil ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17592&edit=1

« previous php.bugs (#9515) next »