cvs: /php3 ChangeLog php3.ini-dist /php3/functions basic_functions.c basic_functions.h

From: Date: Wed, 23 Feb 2000 22:57:21 +0000
Subject: cvs: /php3 ChangeLog php3.ini-dist /php3/functions basic_functions.c basic_functions.h
Groups: php.dev 
Request: Send a blank email to php-dev+get-15911@lists.php.net to get a copy of this message
zeev Wed Feb 23 14:57:21 2000 EDT Modified files: /php3 ChangeLog php3.ini-dist /php3/functions basic_functions.c basic_functions.h Log: Backport safe_mode_protected_env_vars and safe_mode_allowed_env_vars Index: php3/ChangeLog diff -u php3/ChangeLog:1.825 php3/ChangeLog:1.826 --- php3/ChangeLog:1.825 Tue Feb 22 06:55:17 2000 +++ php3/ChangeLog Wed Feb 23 14:57:21 2000 @@ -2,6 +2,8 @@ ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| February 22, Version 3.0.15 +- Backported safe_mode_protected_env_vars and safe_mode_allowed_env_vars INI + directives from PHP 4.0 (Zeev) - Added Matthew Herman's FTP module patch for compatibility with Microsoft FTP service. (Andrew Skalski) - Fixed crash in strip_tags() and related functions. Index: php3/php3.ini-dist diff -u php3/php3.ini-dist:1.56 php3/php3.ini-dist:1.57 --- php3/php3.ini-dist:1.56 Sat Jan 29 11:33:04 2000 +++ php3/php3.ini-dist Wed Feb 23 14:57:21 2000 @@ -38,9 +38,32 @@ asp_tags = Off ; allow ASP-style <% %> tags precision = 14 ; number of significant digits displayed in floating point numbers y2k_compliance = Off ; whether to be year 2000 compliant (will cause problems with non y2k compliant browsers) + ; Safe Mode safe_mode = Off safe_mode_exec_dir = +safe_mode_allowed_env_vars = PHP_ ; Setting certain environment variables + ; may be a potential security breach. + ; This directive contains a comma-delimited + ; list of prefixes. In Safe Mode, the + ; user may only alter environment + ; variables whose names begin with the + ; prefixes supplied here. + ; By default, users will only be able + ; to set environment variables that begin + ; with PHP_ (e.g. PHP_FOO=BAR). + ; Note: If this directive is empty, PHP + ; will let the user modify ANY environment + ; variable! +safe_mode_protected_env_vars = LD_LIBRARY_PATH ; This directive contains a comma- + ; delimited list of environment variables, + ; that the end user won't be able to + ; change using putenv(). + ; These variables will be protected + ; even if safe_mode_allowed_env_vars is + ; set to allow to change them. + + ; Colors for Syntax Highlighting mode. Anything that's acceptable in <font color=???> would work. highlight.string = #DD0000 highlight.comment = #FF8000 Index: php3/functions/basic_functions.c diff -u php3/functions/basic_functions.c:1.284 php3/functions/basic_functions.c:1.285 --- php3/functions/basic_functions.c:1.284 Mon Feb 7 15:54:51 2000 +++ php3/functions/basic_functions.c Wed Feb 23 14:57:21 2000 @@ -28,7 +28,7 @@ +----------------------------------------------------------------------+ */ -/* $Id: basic_functions.c,v 1.284 2000/02/07 23:54:51 zeev Exp $ */ +/* $Id: basic_functions.c,v 1.285 2000/02/23 22:57:21 zeev Exp $ */ #include "php.h" #include "modules.h" #include "internal_functions.h" @@ -100,6 +100,12 @@ static pval *user_compare_func_name; static HashTable *user_shutdown_function_names; +#if HAVE_PUTENV +static HashTable sm_protected_env_vars; +static char *sm_allowed_env_vars; +#endif + + /* some prototypes for local functions */ void user_shutdown_function_dtor(pval *user_shutdown_function_name); int user_shutdown_function_executor(pval *user_shutdown_function_name); @@ -345,7 +351,7 @@ "Basic Functions", /* extension name */ basic_functions, /* function list */ php3_minit_basic, /* process startup */ - NULL, /* process shutdown */ + php3_mshutdown_basic, /* process shutdown */ php3_rinit_basic, /* request startup */ php3_rshutdown_basic, /* request shutdown */ NULL, /* extension info */ @@ -389,6 +395,7 @@ int php3_minit_basic(INIT_FUNC_ARGS) { + char *protected_vars, *protected_var; TLS_VARS; REGISTER_DOUBLE_CONSTANT("M_PI", M_PI, CONST_CS | CONST_PERSISTENT); @@ -397,9 +404,39 @@ REGISTER_LONG_CONSTANT("EXTR_SKIP", EXTR_SKIP, CONST_CS | CONST_PERSISTENT); REGISTER_LONG_CONSTANT("EXTR_PREFIX_SAME", EXTR_PREFIX_SAME, CONST_CS | CONST_PERSISTENT); REGISTER_LONG_CONSTANT("EXTR_PREFIX_ALL", EXTR_PREFIX_ALL, CONST_CS | CONST_PERSISTENT); + + _php3_hash_init(&sm_protected_env_vars, 5, NULL, NULL, 1); + + if (cfg_get_string("safe_mode_protected_env_vars", &protected_vars) == FAILURE) { + protected_vars = NULL; + } + + if (protected_vars) { + int dummy=1; + + protected_vars = estrdup(protected_vars); + protected_var=strtok(protected_vars, ", "); + while (protected_var) { + _php3_hash_update(&sm_protected_env_vars, protected_var, strlen(protected_var), &dummy, sizeof(int), NULL); + protected_var=strtok(NULL, ", "); + } + efree(protected_vars); + } + + if (cfg_get_string("safe_mode_allowed_env_vars", &sm_allowed_env_vars) == FAILURE) { + sm_allowed_env_vars = NULL; + } + return SUCCESS; } + +int php3_mshutdown_basic(void) +{ + _php3_hash_destroy(&sm_protected_env_vars); +} + + int php3_rinit_basic(INIT_FUNC_ARGS) { TLS_VARS; @@ -516,6 +553,38 @@ pe.key_len = strlen(pe.key); pe.key = estrndup(pe.key,pe.key_len); + if (php3_ini.safe_mode) { + /* Check the protected list */ + if (_php3_hash_exists(&sm_protected_env_vars, pe.key, pe.key_len)) { + php3_error(E_WARNING, "Safe Mode: Cannot override protected environment variable '%s'", pe.key); + efree(pe.putenv_string); + efree(pe.key); + RETURN_FALSE; + } + + /* Check the allowed list */ + if (sm_allowed_env_vars && *sm_allowed_env_vars) { + char *allowed_env_vars = estrdup(sm_allowed_env_vars); + char *allowed_prefix = strtok(allowed_env_vars, ", "); + unsigned char allowed=0; + + while (allowed_prefix) { + if (!strncmp(allowed_prefix, pe.key, strlen(allowed_prefix))) { + allowed=1; + break; + } + allowed_prefix = strtok(NULL, ", "); + } + efree(allowed_env_vars); + if (!allowed) { + php3_error(E_WARNING, "Safe Mode: Cannot set environment variable '%s' - it's not in the allowed list", pe.key); + efree(pe.putenv_string); + efree(pe.key); + RETURN_FALSE; + } + } + } + _php3_hash_del(&putenv_ht,pe.key,pe.key_len+1); /* find previous value */ Index: php3/functions/basic_functions.h diff -u php3/functions/basic_functions.h:1.46 php3/functions/basic_functions.h:1.47 --- php3/functions/basic_functions.h:1.46 Mon Feb 7 15:54:51 2000 +++ php3/functions/basic_functions.h Wed Feb 23 14:57:21 2000 @@ -29,7 +29,7 @@ */ -/* $Id: basic_functions.h,v 1.46 2000/02/07 23:54:51 zeev Exp $ */ +/* $Id: basic_functions.h,v 1.47 2000/02/23 22:57:21 zeev Exp $ */ #ifndef _BASIC_FUNCTIONS_H #define _BASIC_FUNCTIONS_H @@ -38,6 +38,7 @@ #define basic_functions_module_ptr &basic_functions_module extern int php3_minit_basic(INIT_FUNC_ARGS); +extern int php3_mshutdown_basic(void); extern int php3_rinit_basic(INIT_FUNC_ARGS); extern int php3_rshutdown_basic(void); extern void int_value(INTERNAL_FUNCTION_PARAMETERS);

« previous php.dev (#15911) next »