Re: ENFORCE_SAFE_MODE

From: Date: Wed, 30 Aug 2000 20:38:57 +0000
Subject: Re: ENFORCE_SAFE_MODE
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-31312@lists.php.net to get a copy of this message
> >?? How does that solve anything? There is nothing special about the > >nobody user. Safe mode would still reject the file access. > > I guess I missed something then. I thought that you can open files which > have the same uid as the web server in safe_mode. No, the whole point of safe mode is that you can only open files that are owned by the same user id that owns the script currently being executed. PHP scripts are typically not owned by nobody. They are owned by whichever user created them. > Well there's not much to say except "it sucks very very badly right now". I > will concentrate right now on cleaning up the code without changing the > semantics and maybe then it'll be easier to see what needs to be changed. Perhaps flip the logic. Instead of explicitly enforcing safe mode, change it so that you have to explicitly disable safe mode. That will make those places where we do that stand out better as well. -Rasmus

« previous php.dev (#31312) next »