cvs: php4 /main php_streams.h safe_mode.c streams.c

From: Date: Fri, 16 Aug 2002 09:50:24 +0000
Subject: cvs: php4 /main php_streams.h safe_mode.c streams.c
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-13401@lists.php.net to get a copy of this message
wez Fri Aug 16 05:50:24 2002 EDT Modified files: /php4/main php_streams.h safe_mode.c streams.c Log: Enhance Ilia's recent patch to query the wrapper subsystem to determine if a filename is a URL and thus if safe-mode checks should be skipped. Index: php4/main/php_streams.h diff -u php4/main/php_streams.h:1.36 php4/main/php_streams.h:1.37 --- php4/main/php_streams.h:1.36 Sun Aug 11 10:29:01 2002 +++ php4/main/php_streams.h Fri Aug 16 05:50:23 2002 @@ -370,6 +370,9 @@ * */ #define STREAM_WILL_CAST 32 +/* this flag applies to php_stream_locate_url_wrapper */ +#define STREAM_LOCATE_WRAPPERS_ONLY 64 + #ifdef PHP_WIN32 # define IGNORE_URL_WIN IGNORE_URL #else @@ -381,6 +384,7 @@ PHPAPI int php_register_url_stream_wrapper(char *protocol, php_stream_wrapper *wrapper TSRMLS_DC); PHPAPI int php_unregister_url_stream_wrapper(char *protocol TSRMLS_DC); PHPAPI php_stream *_php_stream_open_wrapper_ex(char *path, char *mode, int options, char **opened_path, php_stream_context *context STREAMS_DC TSRMLS_DC); +PHPAPI php_stream_wrapper *php_stream_locate_url_wrapper(const char *path, char **path_for_open, int options TSRMLS_DC); #define php_stream_open_wrapper(path, mode, options, opened) _php_stream_open_wrapper_ex((path), (mode), (options), (opened), NULL STREAMS_CC TSRMLS_CC) #define php_stream_open_wrapper_ex(path, mode, options, opened, context) _php_stream_open_wrapper_ex((path), (mode), (options), (opened), (context) STREAMS_CC TSRMLS_CC) Index: php4/main/safe_mode.c diff -u php4/main/safe_mode.c:1.47 php4/main/safe_mode.c:1.48 --- php4/main/safe_mode.c:1.47 Thu Aug 15 23:52:37 2002 +++ php4/main/safe_mode.c Fri Aug 16 05:50:24 2002 @@ -15,7 +15,7 @@ | Author: Rasmus Lerdorf <rasmus@lerdorf.on.ca> | +----------------------------------------------------------------------+ */ -/* $Id: safe_mode.c,v 1.47 2002/08/16 03:52:37 iliaa Exp $ */ +/* $Id: safe_mode.c,v 1.48 2002/08/16 09:50:24 wez Exp $ */ #include "php.h" @@ -52,6 +52,7 @@ long uid=0L, gid=0L, duid=0L, dgid=0L; char path[MAXPATHLEN]; char *s, filenamecopy[MAXPATHLEN]; + php_stream_wrapper *wrapper = NULL; TSRMLS_FETCH(); strlcpy(filenamecopy, filename, MAXPATHLEN); @@ -73,9 +74,9 @@ * If given filepath is a URL, allow - safe mode stuff * related to URL's is checked in individual functions */ - if (!strncasecmp(filename,"http://", 7) || !strncasecmp(filename,"ftp://", 6) || !strncasecmp(filename,"https://", 8)) { + wrapper = php_stream_locate_url_wrapper(filename, NULL, STREAM_LOCATE_WRAPPERS_ONLY TSRMLS_CC); + if (wrapper != NULL) return 1; - } /* First we see if the file is owned by the same user... * If that fails, passthrough and check directory... Index: php4/main/streams.c diff -u php4/main/streams.c:1.60 php4/main/streams.c:1.61 --- php4/main/streams.c:1.60 Sun Aug 11 06:53:10 2002 +++ php4/main/streams.c Fri Aug 16 05:50:24 2002 @@ -20,7 +20,7 @@ +----------------------------------------------------------------------+ */ -/* $Id: streams.c,v 1.60 2002/08/11 10:53:10 wez Exp $ */ +/* $Id: streams.c,v 1.61 2002/08/16 09:50:24 wez Exp $ */ #define _GNU_SOURCE #include "php.h" @@ -1166,16 +1166,17 @@ 0 }; -static php_stream_wrapper *locate_url_wrapper(char *path, char **path_for_open, int options TSRMLS_DC) +PHPAPI php_stream_wrapper *php_stream_locate_url_wrapper(const char *path, char **path_for_open, int options TSRMLS_DC) { php_stream_wrapper *wrapper = NULL; const char *p, *protocol = NULL; int n = 0; - *path_for_open = path; + if (path_for_open) + *path_for_open = (char*)path; if (options & IGNORE_URL) - return &php_plain_files_wrapper; + return (options & STREAM_LOCATE_WRAPPERS_ONLY) ? NULL : &php_plain_files_wrapper; for (p = path; isalnum((int)*p) || *p == '+' || *p == '-' || *p == '.'; p++) { n++; @@ -1205,20 +1206,23 @@ protocol = NULL; } } + /* TODO: curl based streams probably support file:// properly */ if (!protocol || !strncasecmp(protocol, "file", n)) { if (protocol && path[n+1] == '/' && path[n+2] == '/') { - zend_error(E_WARNING, "remote host file access not supported, %s", path); + if (options & REPORT_ERRORS) + zend_error(E_WARNING, "remote host file access not supported, %s", path); return NULL; } - if (protocol) - *path_for_open = path + n + 1; + if (protocol && path_for_open) + *path_for_open = (char*)path + n + 1; /* fall back on regular file access */ - return &php_plain_files_wrapper; + return (options & STREAM_LOCATE_WRAPPERS_ONLY) ? NULL : &php_plain_files_wrapper; } if (wrapper && wrapper->is_url && !PG(allow_url_fopen)) { - zend_error(E_WARNING, "URL file-access is disabled in the server configuration"); + if (options & REPORT_ERRORS) + zend_error(E_WARNING, "URL file-access is disabled in the server configuration"); return NULL; } @@ -1230,7 +1234,7 @@ php_stream_wrapper *wrapper = NULL; char *path_to_open = path; - wrapper = locate_url_wrapper(path, &path_to_open, ENFORCE_SAFE_MODE TSRMLS_CC); + wrapper = php_stream_locate_url_wrapper(path, &path_to_open, ENFORCE_SAFE_MODE TSRMLS_CC); if (wrapper && wrapper->wops->url_stat) { return wrapper->wops->url_stat(wrapper, path_to_open, ssb TSRMLS_CC); } @@ -1250,7 +1254,7 @@ path_to_open = path; - wrapper = locate_url_wrapper(path, &path_to_open, options TSRMLS_CC); + wrapper = php_stream_locate_url_wrapper(path, &path_to_open, options TSRMLS_CC); if (wrapper && wrapper->wops->dir_opener) { stream = wrapper->wops->dir_opener(wrapper, @@ -1322,7 +1326,7 @@ path_to_open = path; - wrapper = locate_url_wrapper(path, &path_to_open, options TSRMLS_CC); + wrapper = php_stream_locate_url_wrapper(path, &path_to_open, options TSRMLS_CC); if (wrapper) {

« previous php.cvs (#13401) next »