cvs: /php3 ChangeLog php3.ini-dist /php3/functions basic_functions.c basic_functions.h
| From: | Zeev Suraski | Date: | Wed, 23 Feb 2000 22:57:21 +0000 |
| Subject: | cvs: /php3 ChangeLog php3.ini-dist /php3/functions basic_functions.c basic_functions.h | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-15911@lists.php.net to get a copy of this message | ||
zeev Wed Feb 23 14:57:21 2000 EDT
Modified files:
/php3 ChangeLog php3.ini-dist
/php3/functions basic_functions.c basic_functions.h
Log:
Backport safe_mode_protected_env_vars and safe_mode_allowed_env_vars
Index: php3/ChangeLog
diff -u php3/ChangeLog:1.825 php3/ChangeLog:1.826
--- php3/ChangeLog:1.825 Tue Feb 22 06:55:17 2000
+++ php3/ChangeLog Wed Feb 23 14:57:21 2000
@@ -2,6 +2,8 @@
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
February 22, Version 3.0.15
+- Backported safe_mode_protected_env_vars and safe_mode_allowed_env_vars INI
+ directives from PHP 4.0 (Zeev)
- Added Matthew Herman's FTP module patch for compatibility with Microsoft
FTP service. (Andrew Skalski)
- Fixed crash in strip_tags() and related functions.
Index: php3/php3.ini-dist
diff -u php3/php3.ini-dist:1.56 php3/php3.ini-dist:1.57
--- php3/php3.ini-dist:1.56 Sat Jan 29 11:33:04 2000
+++ php3/php3.ini-dist Wed Feb 23 14:57:21 2000
@@ -38,9 +38,32 @@
asp_tags = Off ; allow ASP-style <% %> tags
precision = 14 ; number of significant digits displayed in floating point numbers
y2k_compliance = Off ; whether to be year 2000 compliant (will cause problems with non y2k
compliant browsers)
+
; Safe Mode
safe_mode = Off
safe_mode_exec_dir =
+safe_mode_allowed_env_vars = PHP_ ; Setting certain environment variables
+ ; may be a potential security breach.
+ ; This directive contains a comma-delimited
+ ; list of prefixes. In Safe Mode, the
+ ; user may only alter environment
+ ; variables whose names begin with the
+ ; prefixes supplied here.
+ ; By default, users will only be able
+ ; to set environment variables that begin
+ ; with PHP_ (e.g. PHP_FOO=BAR).
+ ; Note: If this directive is empty, PHP
+ ; will let the user modify ANY environment
+ ; variable!
+safe_mode_protected_env_vars = LD_LIBRARY_PATH ; This directive contains a comma-
+ ; delimited list of environment variables,
+ ; that the end user won't be able to
+ ; change using putenv().
+ ; These variables will be protected
+ ; even if safe_mode_allowed_env_vars is
+ ; set to allow to change them.
+
+
; Colors for Syntax Highlighting mode. Anything that's acceptable in <font color=???>
would work.
highlight.string = #DD0000
highlight.comment = #FF8000
Index: php3/functions/basic_functions.c
diff -u php3/functions/basic_functions.c:1.284 php3/functions/basic_functions.c:1.285
--- php3/functions/basic_functions.c:1.284 Mon Feb 7 15:54:51 2000
+++ php3/functions/basic_functions.c Wed Feb 23 14:57:21 2000
@@ -28,7 +28,7 @@
+----------------------------------------------------------------------+
*/
-/* $Id: basic_functions.c,v 1.284 2000/02/07 23:54:51 zeev Exp $ */
+/* $Id: basic_functions.c,v 1.285 2000/02/23 22:57:21 zeev Exp $ */
#include "php.h"
#include "modules.h"
#include "internal_functions.h"
@@ -100,6 +100,12 @@
static pval *user_compare_func_name;
static HashTable *user_shutdown_function_names;
+#if HAVE_PUTENV
+static HashTable sm_protected_env_vars;
+static char *sm_allowed_env_vars;
+#endif
+
+
/* some prototypes for local functions */
void user_shutdown_function_dtor(pval *user_shutdown_function_name);
int user_shutdown_function_executor(pval *user_shutdown_function_name);
@@ -345,7 +351,7 @@
"Basic Functions", /* extension name */
basic_functions, /* function list */
php3_minit_basic, /* process startup */
- NULL, /* process shutdown */
+ php3_mshutdown_basic, /* process shutdown */
php3_rinit_basic, /* request startup */
php3_rshutdown_basic, /* request shutdown */
NULL, /* extension info */
@@ -389,6 +395,7 @@
int php3_minit_basic(INIT_FUNC_ARGS)
{
+ char *protected_vars, *protected_var;
TLS_VARS;
REGISTER_DOUBLE_CONSTANT("M_PI", M_PI, CONST_CS | CONST_PERSISTENT);
@@ -397,9 +404,39 @@
REGISTER_LONG_CONSTANT("EXTR_SKIP", EXTR_SKIP, CONST_CS | CONST_PERSISTENT);
REGISTER_LONG_CONSTANT("EXTR_PREFIX_SAME", EXTR_PREFIX_SAME, CONST_CS |
CONST_PERSISTENT);
REGISTER_LONG_CONSTANT("EXTR_PREFIX_ALL", EXTR_PREFIX_ALL, CONST_CS | CONST_PERSISTENT);
+
+ _php3_hash_init(&sm_protected_env_vars, 5, NULL, NULL, 1);
+
+ if (cfg_get_string("safe_mode_protected_env_vars", &protected_vars) == FAILURE) {
+ protected_vars = NULL;
+ }
+
+ if (protected_vars) {
+ int dummy=1;
+
+ protected_vars = estrdup(protected_vars);
+ protected_var=strtok(protected_vars, ", ");
+ while (protected_var) {
+ _php3_hash_update(&sm_protected_env_vars, protected_var, strlen(protected_var), &dummy,
sizeof(int), NULL);
+ protected_var=strtok(NULL, ", ");
+ }
+ efree(protected_vars);
+ }
+
+ if (cfg_get_string("safe_mode_allowed_env_vars", &sm_allowed_env_vars) == FAILURE) {
+ sm_allowed_env_vars = NULL;
+ }
+
return SUCCESS;
}
+
+int php3_mshutdown_basic(void)
+{
+ _php3_hash_destroy(&sm_protected_env_vars);
+}
+
+
int php3_rinit_basic(INIT_FUNC_ARGS)
{
TLS_VARS;
@@ -516,6 +553,38 @@
pe.key_len = strlen(pe.key);
pe.key = estrndup(pe.key,pe.key_len);
+ if (php3_ini.safe_mode) {
+ /* Check the protected list */
+ if (_php3_hash_exists(&sm_protected_env_vars, pe.key, pe.key_len)) {
+ php3_error(E_WARNING, "Safe Mode: Cannot override protected environment variable
'%s'", pe.key);
+ efree(pe.putenv_string);
+ efree(pe.key);
+ RETURN_FALSE;
+ }
+
+ /* Check the allowed list */
+ if (sm_allowed_env_vars && *sm_allowed_env_vars) {
+ char *allowed_env_vars = estrdup(sm_allowed_env_vars);
+ char *allowed_prefix = strtok(allowed_env_vars, ", ");
+ unsigned char allowed=0;
+
+ while (allowed_prefix) {
+ if (!strncmp(allowed_prefix, pe.key, strlen(allowed_prefix))) {
+ allowed=1;
+ break;
+ }
+ allowed_prefix = strtok(NULL, ", ");
+ }
+ efree(allowed_env_vars);
+ if (!allowed) {
+ php3_error(E_WARNING, "Safe Mode: Cannot set environment variable '%s' -
it's not in the allowed list", pe.key);
+ efree(pe.putenv_string);
+ efree(pe.key);
+ RETURN_FALSE;
+ }
+ }
+ }
+
_php3_hash_del(&putenv_ht,pe.key,pe.key_len+1);
/* find previous value */
Index: php3/functions/basic_functions.h
diff -u php3/functions/basic_functions.h:1.46 php3/functions/basic_functions.h:1.47
--- php3/functions/basic_functions.h:1.46 Mon Feb 7 15:54:51 2000
+++ php3/functions/basic_functions.h Wed Feb 23 14:57:21 2000
@@ -29,7 +29,7 @@
*/
-/* $Id: basic_functions.h,v 1.46 2000/02/07 23:54:51 zeev Exp $ */
+/* $Id: basic_functions.h,v 1.47 2000/02/23 22:57:21 zeev Exp $ */
#ifndef _BASIC_FUNCTIONS_H
#define _BASIC_FUNCTIONS_H
@@ -38,6 +38,7 @@
#define basic_functions_module_ptr &basic_functions_module
extern int php3_minit_basic(INIT_FUNC_ARGS);
+extern int php3_mshutdown_basic(void);
extern int php3_rinit_basic(INIT_FUNC_ARGS);
extern int php3_rshutdown_basic(void);
extern void int_value(INTERNAL_FUNCTION_PARAMETERS);