CVS update: php31/main

From: Date: Thu, 13 Aug 1998 23:23:28 +0000
Subject: CVS update: php31/main
Groups: php.dev 
Request: Send a blank email to php-dev+get-190@lists.php.net to get a copy of this message
Date: Thursday August 13, 1998 @ 19:23 Author: shane Update of /repository/php31/main In directory asf:/tmp/cvs-serv8944/main Modified Files: fopen-wrappers.c fopen-wrappers.h php3_realpath.c phpsapi_core.dsp Log Message: 3.0->3.1 patches Index: php31/main/fopen-wrappers.c diff -c php31/main/fopen-wrappers.c:2.0 php31/main/fopen-wrappers.c:2.1 *** php31/main/fopen-wrappers.c:2.0 Fri Jul 3 09:17:15 1998 --- php31/main/fopen-wrappers.c Thu Aug 13 19:23:27 1998 *************** *** 27,33 **** | Jim Winstead <jimw@php.net> | +----------------------------------------------------------------------+ */ ! /* $Id: fopen-wrappers.c,v 2.0 1998/07/03 13:17:15 rasmus Exp $ */ #ifdef THREAD_SAFE #include "tls.h" --- 27,33 ---- | Jim Winstead <jimw@php.net> | +----------------------------------------------------------------------+ */ ! /* $Id: fopen-wrappers.c,v 2.1 1998/08/13 23:23:27 shane Exp $ */ #ifdef THREAD_SAFE #include "tls.h" *************** *** 54,59 **** --- 54,60 ---- #include "safe_mode.h" #include "php3_list.h" + #include "php3_realpath.h" #include "head.h" #include "ext/standard/url.h" #include "ext/standard/base64.h" *************** *** 97,102 **** --- 98,141 ---- int _php3_getftpresult(int socketd); + /* + When fopen_basedir is not NULL, check if the given filename is located in + fopen_basedir. Returns -1 if error or not in the fopen_basedir, else 0 + + When fopen_basedir is NULL, always return 0 + */ + int _php3_check_fopen_basedir(char *path) + { + char resolved_name[MAXPATHLEN]; + TLS_VARS; + + /* Only check when fopen_basedir is available */ + if (GLOBAL(php3_ini)->fopen_basedir && *GLOBAL(php3_ini)->fopen_basedir) { + /* Resolve the real path into resolved_name */ + if (_php3_realpath(path, resolved_name) != NULL) { + /* Check the path */ + #if WIN32|WINNT + if (strncmp(GLOBAL(php3_ini)->fopen_basedir, resolved_name, strlen(GLOBAL(php3_ini)->fopen_basedir)) == 0) { + #else + if (strncasecmp(GLOBAL(php3_ini)->fopen_basedir, resolved_name, strlen(GLOBAL(php3_ini)->fopen_basedir)) == 0) { + #endif + /* File is in the right directory */ + return 0; + } else { + php3_error(E_WARNING, "fopen_basedir restriction in effect. File is in wrong directory."); + return -1; + } + } else { + /* Unable to resolve the real path, return -1 */ + php3_error(E_WARNING, "fopen_basedir restriction in effect. Unable to verify location of file."); + return -1; + } + } else { + /* fopen_basedir is not available, return 0 */ + return 0; + } + } + PHPAPI FILE *php3_fopen_wrapper(char *path, char *mode, int options, int *issock, int *socketd) { TLS_VARS; *************** *** 229,234 **** --- 268,274 ---- php3_error(E_WARNING, "SAFE MODE Restriction in effect. Invalid owner."); return NULL; } + if (_php3_check_fopen_basedir(filename)) return NULL; fp = fopen(filename, mode); if (fp && opened_path) { *opened_path = expand_filepath(filename); *************** *** 247,258 **** --- 287,300 ---- php3_error(E_WARNING, "SAFE MODE Restriction in effect. Invalid owner."); return NULL; } + if (_php3_check_fopen_basedir(trypath)) return NULL; fp = fopen(trypath, mode); if (fp && opened_path) { *opened_path = expand_filepath(trypath); } return fp; } else { + if (_php3_check_fopen_basedir(filename)) return NULL; return fopen(filename, mode); } } *************** *** 261,266 **** --- 303,309 ---- php3_error(E_WARNING, "SAFE MODE Restriction in effect. Invalid owner."); return NULL; } + if (_php3_check_fopen_basedir(filename)) return NULL; fp = fopen(filename, mode); if (fp && opened_path) { *opened_path = strdup(filename); *************** *** 290,295 **** --- 333,343 ---- } } if ((fp = fopen(trypath, mode)) != NULL) { + if (_php3_check_fopen_basedir(trypath)) { + fclose(fp); + efree(pathbuf); + return NULL; + } if (opened_path) { *opened_path = expand_filepath(trypath); } *************** *** 615,626 **** /* read the response */ result = _php3_getftpresult(*socketd); ! if (result > 299 || result < 200) { ! free_url(resource); ! SOCK_FCLOSE(*socketd); ! *socketd = 0; ! return NULL; ! } /* set the connection to be binary */ SOCK_WRITE("TYPE I\n", *socketd); result = _php3_getftpresult(*socketd); --- 663,690 ---- /* read the response */ result = _php3_getftpresult(*socketd); ! if (mode[0] == 'r') { ! /* when reading file, it must exist */ ! if (result > 299 || result < 200) { ! php3_error(E_WARNING, "File not found"); ! free_url(resource); ! SOCK_FCLOSE(*socketd); ! *socketd = 0; ! errno = ENOENT; ! return NULL; ! } ! } else { ! /* when writing file, it must NOT exist */ ! if (result <= 299 && result >= 200) { ! php3_error(E_WARNING, "File already exists"); ! free_url(resource); ! SOCK_FCLOSE(*socketd); ! *socketd = 0; ! errno = EEXIST; ! return NULL; ! } ! } ! /* set the connection to be binary */ SOCK_WRITE("TYPE I\n", *socketd); result = _php3_getftpresult(*socketd); *************** *** 697,708 **** } /* finally, send a message to start retrieving the file, and close the command connection */ ! SOCK_WRITE("RETR ", *socketd); if (resource->path != NULL) { SOCK_WRITE(resource->path, *socketd); } else { SOCK_WRITE("/", *socketd); } SOCK_WRITE("\nQUIT\n", *socketd); SOCK_FCLOSE(*socketd); --- 761,781 ---- } /* finally, send a message to start retrieving the file, and close the command connection */ ! if (mode[0] == 'r') { ! /* retrieve file */ ! SOCK_WRITE("RETR ", *socketd); ! } else { ! /* store file */ ! SOCK_WRITE("STOR ", *socketd); ! } ! if (resource->path != NULL) { SOCK_WRITE(resource->path, *socketd); } else { SOCK_WRITE("/", *socketd); } + + /*close connection*/ SOCK_WRITE("\nQUIT\n", *socketd); SOCK_FCLOSE(*socketd); *************** *** 732,741 **** return NULL; } #if 0 ! if ((fp = fdopen(*socketd, "r+")) == NULL) { ! free_url(resource); ! return NULL; ! } #ifdef HAVE_SETVBUF if ((setvbuf(fp, NULL, _IONBF, 0)) != 0) { free_url(resource); --- 805,821 ---- return NULL; } #if 0 ! if (mode[0] == 'r') { ! if ((fp = fdopen(*socketd, "r+")) == NULL) { ! free_url(resource); ! return NULL; ! } ! } else { ! if ((fp = fdopen(*socketd, "w+")) == NULL) { ! free_url(resource); ! return NULL; ! } ! } #ifdef HAVE_SETVBUF if ((setvbuf(fp, NULL, _IONBF, 0)) != 0) { free_url(resource); Index: php31/main/fopen-wrappers.h diff -c php31/main/fopen-wrappers.h:2.0 php31/main/fopen-wrappers.h:2.1 *** php31/main/fopen-wrappers.h:2.0 Fri Jul 3 09:17:16 1998 --- php31/main/fopen-wrappers.h Thu Aug 13 19:23:28 1998 *************** *** 26,32 **** | Authors: Jim Winstead <jimw@php.net> | +----------------------------------------------------------------------+ */ ! /* $Id: fopen-wrappers.h,v 2.0 1998/07/03 13:17:16 rasmus Exp $ */ #ifndef _FOPEN_WRAPPERS_H #define _FOPEN_WRAPPERS_H --- 26,32 ---- | Authors: Jim Winstead <jimw@php.net> | +----------------------------------------------------------------------+ */ ! /* $Id: fopen-wrappers.h,v 2.1 1998/08/13 23:23:28 shane Exp $ */ #ifndef _FOPEN_WRAPPERS_H #define _FOPEN_WRAPPERS_H *************** *** 78,84 **** extern PHPAPI int php3_write(void *buf, int size); extern PHPAPI char *expand_filepath(char *filepath); ! #endif /* * Local variables: --- 78,84 ---- extern PHPAPI int php3_write(void *buf, int size); extern PHPAPI char *expand_filepath(char *filepath); ! extern int _php3_check_fopen_basedir(char *path); #endif /* * Local variables: Index: php31/main/php3_realpath.c diff -c php31/main/php3_realpath.c:1.1 php31/main/php3_realpath.c:1.2 *** php31/main/php3_realpath.c:1.1 Thu Aug 13 18:59:30 1998 --- php31/main/php3_realpath.c Thu Aug 13 19:23:28 1998 *************** *** 54,62 **** char path_copy[MAXPATHLEN]; /* A work-copy of the path */ char *workpos; /* working position in *path */ ! char buf[MAXPATHLEN]; /* Buffer for readlink */ int linklength; /* The result from readlink */ int linkcount = 0; /* Count symlinks to avoid loops */ struct stat filestat; /* result from stat */ --- 54,63 ---- char path_copy[MAXPATHLEN]; /* A work-copy of the path */ char *workpos; /* working position in *path */ ! #if !(WIN32|WINNT) char buf[MAXPATHLEN]; /* Buffer for readlink */ int linklength; /* The result from readlink */ + #endif int linkcount = 0; /* Count symlinks to avoid loops */ struct stat filestat; /* result from stat */ Index: php31/main/phpsapi_core.dsp diff -c php31/main/phpsapi_core.dsp:2.2 php31/main/phpsapi_core.dsp:2.3 *** php31/main/phpsapi_core.dsp:2.2 Fri Jul 17 13:23:11 1998 --- php31/main/phpsapi_core.dsp Thu Aug 13 19:23:28 1998 *************** *** 237,242 **** --- 237,250 ---- # End Source File # Begin Source File + SOURCE=.\php3_realpath.c + # End Source File + # Begin Source File + + SOURCE=.\php3_realpath.h + # End Source File + # Begin Source File + SOURCE=.\php3_threads.c # End Source File # Begin Source File -- PHP Development Mailing List http://www.php.net/ To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net For help: php-dev-help@lists.php.net

« previous php.dev (#190) next »