patch to safe_mode
| From: | Nabil Edelbi | Date: | Mon, 28 Feb 2000 11:41:18 +0000 |
| Subject: | patch to safe_mode | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-16091@lists.php.net to get a copy of this message | ||
* Scene:
I currently run Apache with mod_php3 and many VirtualHosts. Therefore I
activated safe_mode with safe_mode_exec_dir empty and open_basedir set to
VirtualHosts DocumentRoot. This way the VirtualHosts are not able to access
each others files nor do they have access to any system files. Great thing!
* Problem:
Now SAFE MODE has the Restriction that a skript owned by a FTP user
cannot create directories to store information in it, because the directory
will be created with httpd as it's owner.
* Comments:
Till now, any solution suggested to this problem was to run PHPs
CGI-wrapper with apaches suexec. But this approach does not work with most
important PHP Applications, i.e. phpMyAdmin and others. Generally the CGI
wrapper ist not equivalent to the module.
* Sollution:
Allthough I am sure there must have been a reason for the described
restriction, I applied the following patch to PHPs safe_mode.c to deactivate
it:
112,116c112
< if (duid == (uid=_php3_getuid())) return(1);
< else {
< php3_error(E_WARNING, "SAFE MODE Restriction in effect. The script whose
uid is %ld is not allowed to access %s owned by uid %ld",uid,fn,duid);
< return(0);
< }
---
> return(1);
* Question:
does anybody know what is the aim of this restriction? I cannot immagine what
it is. From my point of view, I do not need this restriction, as I can control
access with unix' access rights.
* Suggestion:
The best thing, I think, would be a new configuration directive in the php3.ini
that can switch on/off this restriction. I would have done it myself to contribute
a patch, but I am not that good in programing C.
Any comments would be appreciated.
Nabil Edelbi