Re: safe_mode and ENFORCE_SAFE_MODE

From: Date: Sat, 19 Aug 2000 13:27:06 +0000
Subject: Re: safe_mode and ENFORCE_SAFE_MODE
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-29644@lists.php.net to get a copy of this message
At 01:15 PM 8/19/00 +0200, Hartmut Holzgraefe (@home) wrote:
Andi Gutmans wrote: Are you talking about PHP_URL_FOPEN? yes, here is what i have done so far: - the only #ifdef PHP_URL_FOPEN thats left in fopen wrappers right now is the one in fhp_fopen_wrapper(), the one with the FixMe comment above
This will change to a PG(allow_url_fopen) ?
- php_fopen_url_wrap_http(), php_fopen_url_wrap_http(), php_fopen_url_wrap_php() and their helper functions have moved to http_fopen_wrapper.c, ftp_fopen_wrapper.c and php_fopen_wrapper.c in ext/standard
Why ext/standard? These are not extension functions they are core functions which should be in main/.
- php_init_fopen_wrappers() will only create the fopen_url_wrappers_hash, no default wrappers registration here - 'ftp:', 'http:' and 'php:' URL methods get registered in ext/standard MINIT()
Again, this is really core functionality and should not be part of ext/standard IMO. The default ones should probably be registered by php_init_fopen_wrappers() or by module_startup() probably the first. BTW, I'm determined to cleanup all of the safe_mode stuff in those files and not to have duplicate code in a zillion of places. Did you read my Email from the other day on removing the following lines from php_url_wrapper()?:
        if (options & USE_PATH) {
                fp = php_fopen_with_path((char *) path, mode, PG(include_path), opened_path);
        } else {
                if (options & ENFORCE_SAFE_MODE && PG(safe_mode) && (!php_checkuid(path, mode, 0))) {
                        fp = NULL;
                } else {
                        fp = php_fopen_and_set_opened_path(path, mode, opened_path);
                }
        }
What should happen is that if the php_url_wrapper() code in php_fopen_wrapper() returns NULL it should go on and do the regular fopen() code. No need to duplicate this code (even if you have to lose that warning at the end of php_url_wrapper()). Please let me know what you think/intend to do. Andi --- Andi Gutmans <andi@zend.com> http://www.zend.com/

« previous php.dev (#29644) next »