Bug #17592 Updated: safe mode doesn't work as described in the manual
| From: | steffann@php.net | Date: | Wed, 05 Jun 2002 09:13:18 +0000 |
| Subject: | Bug #17592 Updated: safe mode doesn't work as described in the manual | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-9526@lists.php.net to get a copy of this message | ||
ID: 17592
Updated by: steffann@php.net
Reported By: fontajos@phpeppershop.org
Status: Bogus
Bug Type: *Configuration Issues
Operating System: SuSE Linux 7.1 Professional
PHP Version: 4.1.2
New Comment:
Hi Jose,
Ofcourse I read your replies :)
This problem is exactly why we don't use safe-mode on our webservers,
and why I made the first implementation of the open_basedir option some
years ago (PHP3).
Good luck,
Sander.
Previous Comments:
------------------------------------------------------------------------
[2002-06-05 04:08:50] fontajos@phpeppershop.org
Thanks for the prompt reply,
It looks like this seems to be the problem it still is. Since PHP
installed as an Apache DSO Module runs every script under the apache's
owner nobody can use the functions that are restricted by the safe_mode
because the ownership comparison will always be false (unless the files
belong to the apache user)...
This situation is unfortunately a bit sad, because if safe_mode would
compare the ownership of the script that is running to the owner of the
file to operate on, it would be no problem to use the functions
restricted by safe mode... still providing the same security...
I propose that this could maybe be changed in a future PHP version. I
hope that you still read this message, since I don't change the status
to open again.
thanks anyway
Jose
------------------------------------------------------------------------
[2002-06-05 03:48:16] steffann@php.net
Sorry, I made a mistake in my response.. getmyuid() actually DOES give
you the owner of the script, not the user which is running the script.
We are looking in the wrong direction here... The error you get is not
from safe-mode. Like you have shown with
fileowner("test2.php") == fileowner("text.txt")
the restrictions for safe-mode are met.
It are the normal UN*X file-access checks that prevent you from writing
to the file. As you can see from
-rwxr-xr-x 1 fontajos users 29 Mai 3 07:17 text.txt
the file may only be opened for writing by user fontajos. Group users
and the rest of the users can only open it for reading and executing
(which is a bit strange for a textfile). The users your webserver runs
as obviously is not user fontajos, so it can not write to the file.
The sollution is to change the access restrictions of the file in a way
that the webserver can open it for writing. The easiest way is to give
_everybody_ write access to the file (chmod a+w file.txt) but that is
not very safe. If your system supports ACLs using them would be a much
better option.
The best thing to do is to ask your ISP/sysadmin/guru what the best
option is for the webserver you are using.
------------------------------------------------------------------------
[2002-06-05 01:20:22] fontajos@phpeppershop.org
...sorry, that was the submit button, a little bit too fast ;-).
You can run the above mentioned script
here:http://phpserver.zhwin.ch/~fontajos/test/test2.php
the comparison is entitled as fileownershop comparison, at the very
bottom.
------------------------------------------------------------------------
[2002-06-05 01:09:07] fontajos@phpeppershop.org
Thank you for the quick reply.
You write, that PHP does the following comparison:
fileowner(\"test2.php\") == fileowner(\"text.txt\");
I tried this within a new script and both, the test2.php and also the
text.txt do have the same UID.
Test:
<?php
echo (fileowner("test3.php")." = ".fileowner("text.txt"));
?>
(You can run this script here:
But still it isn't possible to write to this file or use chmod as
mentioned in the php manual
(http://www.php.net/manual/en/features.safe-mode.php).
------------------------------------------------------------------------
[2002-06-04 07:43:04] steffann@php.net
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
You are comparing the user who *runs* the script (as returned by
getmyuid()) with the owner of file.txt.
Safe mode protection works not by looking at who runs the script, but
by looking at who *owns* the script (as returned by
fileowner(\"test2.php\")).
To give access to the file, safe mode checks for:
fileowner(\"test2.php\") == fileowner(\"text.txt\")
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/17592
--
Edit this bug report at http://bugs.php.net/?id=17592&edit=1