Re: safe_mode and ENFORCE_SAFE_MODE
| From: | Andi Gutmans | Date: | Sat, 19 Aug 2000 00:37:55 +0000 |
| Subject: | Re: safe_mode and ENFORCE_SAFE_MODE | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-29612@lists.php.net to get a copy of this message | ||
At 05:28 PM 8/18/00 -0700, Rasmus Lerdorf wrote:
Any idea why php_fopen_wrapper() accepts the ENFORCE_SAFE_MODE option? Shouldn't it just check PG(safe_mode) like it does in most places? This means that places that call php_fopen_wrapper() and don't explicitly pass the ENFORCE_SAFE_MODE option aren't really safe_mode'ed even under safe_mode. It makes little sense. Well, the obvious answer is that there are places where we use the wrapper without wanting to enforce safe mode. Like when we are loading fonts from the GD extension, for example. It would be inconvenient to copy a directory full of GD fonts into each user's web space.Well for one thing the ENFORCE_SAFE_MODE option doesn't propagate properly throughout fopen-wrappers.c in any case so it's pretty useless. Secondly, I don't know about GD specifically but having the ability to open a non safe-mode file even through a third-party library might open up security holes. Maybe instead there should be an allowed list in safe_mode? This really doesn't seem very secure to me. BTW, php_fopen_wrapper_for_zend() doesn't use this option either which means right now there is not much use to safe_mode (unless I'm missing something). I would really prefer just counting on PG(safe_mode), it would be the clean and sure way of doing things and possible adding a new safe_mode_allowed_dirs variable.
Another thing is why do we still have the --enable-safe-mode compile switch? safe_mode can be set by the system php.ini file. No code as far as I saw actually gives a shit about the PHP_SAFE_MODE being defined by ./configure. IMO yet another thing we can nuke. We have a number of such switches which simply change the default setting. magic-quotes and short-tags from the top of my head.Yeah but this one isn't used. I think we can nuke it. It is best to cut down on compile-time options especially when they aren't needed nor used. Andi --- Andi Gutmans <andi@zend.com> http://www.zend.com/