CVS update: php31/main
| From: | shane | Date: | Thu, 13 Aug 1998 23:23:28 +0000 |
| Subject: | CVS update: php31/main | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-190@lists.php.net to get a copy of this message | ||
Date: Thursday August 13, 1998 @ 19:23
Author: shane
Update of /repository/php31/main
In directory asf:/tmp/cvs-serv8944/main
Modified Files:
fopen-wrappers.c fopen-wrappers.h php3_realpath.c
phpsapi_core.dsp
Log Message:
3.0->3.1 patches
Index: php31/main/fopen-wrappers.c
diff -c php31/main/fopen-wrappers.c:2.0 php31/main/fopen-wrappers.c:2.1
*** php31/main/fopen-wrappers.c:2.0 Fri Jul 3 09:17:15 1998
--- php31/main/fopen-wrappers.c Thu Aug 13 19:23:27 1998
***************
*** 27,33 ****
| Jim Winstead <jimw@php.net> |
+----------------------------------------------------------------------+
*/
! /* $Id: fopen-wrappers.c,v 2.0 1998/07/03 13:17:15 rasmus Exp $ */
#ifdef THREAD_SAFE
#include "tls.h"
--- 27,33 ----
| Jim Winstead <jimw@php.net> |
+----------------------------------------------------------------------+
*/
! /* $Id: fopen-wrappers.c,v 2.1 1998/08/13 23:23:27 shane Exp $ */
#ifdef THREAD_SAFE
#include "tls.h"
***************
*** 54,59 ****
--- 54,60 ----
#include "safe_mode.h"
#include "php3_list.h"
+ #include "php3_realpath.h"
#include "head.h"
#include "ext/standard/url.h"
#include "ext/standard/base64.h"
***************
*** 97,102 ****
--- 98,141 ----
int _php3_getftpresult(int socketd);
+ /*
+ When fopen_basedir is not NULL, check if the given filename is located in
+ fopen_basedir. Returns -1 if error or not in the fopen_basedir, else 0
+
+ When fopen_basedir is NULL, always return 0
+ */
+ int _php3_check_fopen_basedir(char *path)
+ {
+ char resolved_name[MAXPATHLEN];
+ TLS_VARS;
+
+ /* Only check when fopen_basedir is available */
+ if (GLOBAL(php3_ini)->fopen_basedir && *GLOBAL(php3_ini)->fopen_basedir) {
+ /* Resolve the real path into resolved_name */
+ if (_php3_realpath(path, resolved_name) != NULL) {
+ /* Check the path */
+ #if WIN32|WINNT
+ if (strncmp(GLOBAL(php3_ini)->fopen_basedir, resolved_name,
strlen(GLOBAL(php3_ini)->fopen_basedir)) == 0) {
+ #else
+ if (strncasecmp(GLOBAL(php3_ini)->fopen_basedir, resolved_name,
strlen(GLOBAL(php3_ini)->fopen_basedir)) == 0) {
+ #endif
+ /* File is in the right directory */
+ return 0;
+ } else {
+ php3_error(E_WARNING, "fopen_basedir restriction in effect. File is in
wrong directory.");
+ return -1;
+ }
+ } else {
+ /* Unable to resolve the real path, return -1 */
+ php3_error(E_WARNING, "fopen_basedir restriction in effect. Unable to verify
location of file.");
+ return -1;
+ }
+ } else {
+ /* fopen_basedir is not available, return 0 */
+ return 0;
+ }
+ }
+
PHPAPI FILE *php3_fopen_wrapper(char *path, char *mode, int options, int *issock, int *socketd)
{
TLS_VARS;
***************
*** 229,234 ****
--- 268,274 ----
php3_error(E_WARNING, "SAFE MODE Restriction in effect. Invalid owner.");
return NULL;
}
+ if (_php3_check_fopen_basedir(filename)) return NULL;
fp = fopen(filename, mode);
if (fp && opened_path) {
*opened_path = expand_filepath(filename);
***************
*** 247,258 ****
--- 287,300 ----
php3_error(E_WARNING, "SAFE MODE Restriction in effect. Invalid owner.");
return NULL;
}
+ if (_php3_check_fopen_basedir(trypath)) return NULL;
fp = fopen(trypath, mode);
if (fp && opened_path) {
*opened_path = expand_filepath(trypath);
}
return fp;
} else {
+ if (_php3_check_fopen_basedir(filename)) return NULL;
return fopen(filename, mode);
}
}
***************
*** 261,266 ****
--- 303,309 ----
php3_error(E_WARNING, "SAFE MODE Restriction in effect. Invalid owner.");
return NULL;
}
+ if (_php3_check_fopen_basedir(filename)) return NULL;
fp = fopen(filename, mode);
if (fp && opened_path) {
*opened_path = strdup(filename);
***************
*** 290,295 ****
--- 333,343 ----
}
}
if ((fp = fopen(trypath, mode)) != NULL) {
+ if (_php3_check_fopen_basedir(trypath)) {
+ fclose(fp);
+ efree(pathbuf);
+ return NULL;
+ }
if (opened_path) {
*opened_path = expand_filepath(trypath);
}
***************
*** 615,626 ****
/* read the response */
result = _php3_getftpresult(*socketd);
! if (result > 299 || result < 200) {
! free_url(resource);
! SOCK_FCLOSE(*socketd);
! *socketd = 0;
! return NULL;
! }
/* set the connection to be binary */
SOCK_WRITE("TYPE I\n", *socketd);
result = _php3_getftpresult(*socketd);
--- 663,690 ----
/* read the response */
result = _php3_getftpresult(*socketd);
! if (mode[0] == 'r') {
! /* when reading file, it must exist */
! if (result > 299 || result < 200) {
! php3_error(E_WARNING, "File not found");
! free_url(resource);
! SOCK_FCLOSE(*socketd);
! *socketd = 0;
! errno = ENOENT;
! return NULL;
! }
! } else {
! /* when writing file, it must NOT exist */
! if (result <= 299 && result >= 200) {
! php3_error(E_WARNING, "File already exists");
! free_url(resource);
! SOCK_FCLOSE(*socketd);
! *socketd = 0;
! errno = EEXIST;
! return NULL;
! }
! }
!
/* set the connection to be binary */
SOCK_WRITE("TYPE I\n", *socketd);
result = _php3_getftpresult(*socketd);
***************
*** 697,708 ****
}
/* finally, send a message to start retrieving the file, and
close the command connection */
! SOCK_WRITE("RETR ", *socketd);
if (resource->path != NULL) {
SOCK_WRITE(resource->path, *socketd);
} else {
SOCK_WRITE("/", *socketd);
}
SOCK_WRITE("\nQUIT\n", *socketd);
SOCK_FCLOSE(*socketd);
--- 761,781 ----
}
/* finally, send a message to start retrieving the file, and
close the command connection */
! if (mode[0] == 'r') {
! /* retrieve file */
! SOCK_WRITE("RETR ", *socketd);
! } else {
! /* store file */
! SOCK_WRITE("STOR ", *socketd);
! }
!
if (resource->path != NULL) {
SOCK_WRITE(resource->path, *socketd);
} else {
SOCK_WRITE("/", *socketd);
}
+
+ /*close connection*/
SOCK_WRITE("\nQUIT\n", *socketd);
SOCK_FCLOSE(*socketd);
***************
*** 732,741 ****
return NULL;
}
#if 0
! if ((fp = fdopen(*socketd, "r+")) == NULL) {
! free_url(resource);
! return NULL;
! }
#ifdef HAVE_SETVBUF
if ((setvbuf(fp, NULL, _IONBF, 0)) != 0) {
free_url(resource);
--- 805,821 ----
return NULL;
}
#if 0
! if (mode[0] == 'r') {
! if ((fp = fdopen(*socketd, "r+")) == NULL) {
! free_url(resource);
! return NULL;
! }
! } else {
! if ((fp = fdopen(*socketd, "w+")) == NULL) {
! free_url(resource);
! return NULL;
! }
! }
#ifdef HAVE_SETVBUF
if ((setvbuf(fp, NULL, _IONBF, 0)) != 0) {
free_url(resource);
Index: php31/main/fopen-wrappers.h
diff -c php31/main/fopen-wrappers.h:2.0 php31/main/fopen-wrappers.h:2.1
*** php31/main/fopen-wrappers.h:2.0 Fri Jul 3 09:17:16 1998
--- php31/main/fopen-wrappers.h Thu Aug 13 19:23:28 1998
***************
*** 26,32 ****
| Authors: Jim Winstead <jimw@php.net> |
+----------------------------------------------------------------------+
*/
! /* $Id: fopen-wrappers.h,v 2.0 1998/07/03 13:17:16 rasmus Exp $ */
#ifndef _FOPEN_WRAPPERS_H
#define _FOPEN_WRAPPERS_H
--- 26,32 ----
| Authors: Jim Winstead <jimw@php.net> |
+----------------------------------------------------------------------+
*/
! /* $Id: fopen-wrappers.h,v 2.1 1998/08/13 23:23:28 shane Exp $ */
#ifndef _FOPEN_WRAPPERS_H
#define _FOPEN_WRAPPERS_H
***************
*** 78,84 ****
extern PHPAPI int php3_write(void *buf, int size);
extern PHPAPI char *expand_filepath(char *filepath);
!
#endif
/*
* Local variables:
--- 78,84 ----
extern PHPAPI int php3_write(void *buf, int size);
extern PHPAPI char *expand_filepath(char *filepath);
! extern int _php3_check_fopen_basedir(char *path);
#endif
/*
* Local variables:
Index: php31/main/php3_realpath.c
diff -c php31/main/php3_realpath.c:1.1 php31/main/php3_realpath.c:1.2
*** php31/main/php3_realpath.c:1.1 Thu Aug 13 18:59:30 1998
--- php31/main/php3_realpath.c Thu Aug 13 19:23:28 1998
***************
*** 54,62 ****
char path_copy[MAXPATHLEN]; /* A work-copy of the path */
char *workpos; /* working position in *path */
!
char buf[MAXPATHLEN]; /* Buffer for readlink */
int linklength; /* The result from readlink */
int linkcount = 0; /* Count symlinks to avoid loops */
struct stat filestat; /* result from stat */
--- 54,63 ----
char path_copy[MAXPATHLEN]; /* A work-copy of the path */
char *workpos; /* working position in *path */
! #if !(WIN32|WINNT)
char buf[MAXPATHLEN]; /* Buffer for readlink */
int linklength; /* The result from readlink */
+ #endif
int linkcount = 0; /* Count symlinks to avoid loops */
struct stat filestat; /* result from stat */
Index: php31/main/phpsapi_core.dsp
diff -c php31/main/phpsapi_core.dsp:2.2 php31/main/phpsapi_core.dsp:2.3
*** php31/main/phpsapi_core.dsp:2.2 Fri Jul 17 13:23:11 1998
--- php31/main/phpsapi_core.dsp Thu Aug 13 19:23:28 1998
***************
*** 237,242 ****
--- 237,250 ----
# End Source File
# Begin Source File
+ SOURCE=.\php3_realpath.c
+ # End Source File
+ # Begin Source File
+
+ SOURCE=.\php3_realpath.h
+ # End Source File
+ # Begin Source File
+
SOURCE=.\php3_threads.c
# End Source File
# Begin Source File
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net