#37627 [Opn]: session_save_directory checks wrong directory in safe mode
| From: | tony2001@php.net | Date: | Mon, 29 May 2006 12:46:17 +0000 |
| Subject: | #37627 [Opn]: session_save_directory checks wrong directory in safe mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-97745@lists.php.net to get a copy of this message | ||
ID: 37627
Updated by: tony2001@php.net
Reported By: bla at cs dot huji dot ac dot il
Status: Open
Bug Type: Session related
Operating System: freebsd 6.1
PHP Version: 5.1.4
New Comment:
>Note that /var/spool/session exists and has the right
> permissions so there's no need to modify /var/spool).
/var/spool/session or /var/spool/sessions ?
What if try this:
session_save_path("/var/spool/sessions/"); ?
Previous Comments:
------------------------------------------------------------------------
[2006-05-29 12:34:06] bla at cs dot huji dot ac dot il
Description:
------------
When I run this command:
session_save_path("/var/spool/sessions");
I get:
session_save_path() [function.session-save-path]: SAFE MODE Restriction
in effect. The script whose uid is 24713 is not allowed to access
/var/spool
The information in the message is correct but I suppose the function
should check /var/spool/sessions, not /var/spool. (note that
/var/spool/session exists and has the right permissions so there's no
need to modify /var/spool).
Probably the OnUpdateSaveDir() function in session.c should give a
different flag to php_checkuid().
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=37627&edit=1