Re: ENFORCE_SAFE_MODE

From: Date: Wed, 30 Aug 2000 20:20:46 +0000
Subject: Re: ENFORCE_SAFE_MODE
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-31305@lists.php.net to get a copy of this message
At 03:01 PM 8/30/00 -0500, Andrei Zmievski wrote:
On Wed, 30 Aug 2000, Andi Gutmans wrote: Some calls to php_fopen_wrappers() use the ENFORCE_SAFE_MODE #define and some don't. Actually on a whole if you're using include_path you can often circumvent the ENFORCE_SAFE_MODE option and still open a file which you're not supposed to open. I am getting rid of it and am only checking PG(safe_mode) in fopen-wrappers.c. This should make the safe_mode much much safer from now on (at least the code that uses the php_fopen_wrappers()). I have heard in the past that some extension modules might want to open some system fonts and stuff so you wouldn't want to enable safe mode for those modules but I think it's a bad explanation. You could probably use those extensions to open /etc/passwd and maybe even get some kind of info back by chance. If anyone thinks I'll break something badly scream now! As long as you're working on changing php_fopen_wrappers(), I have a wishlist item. Can it be generalized enough so that extensions can use something like PG(include_path) to the files they need from user specified list of directories?
I'm not quite sure what you want. Can you please explain? In any case, my first action item is to clean-up all of this code throughout PHP. It will make it very easy to add additional features later on but right now there are too many modules which are checking PG(safe_mode) && php_checkuid() and so on. It's really ugly and I'm sure full of holes. Andi --- Andi Gutmans <andi@zend.com> http://www.zend.com/

« previous php.dev (#31305) next »