Re: ENFORCE_SAFE_MODE

From: Date: Thu, 07 Sep 2000 13:48:49 +0000
Subject: Re: ENFORCE_SAFE_MODE
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32547@lists.php.net to get a copy of this message
KK>> This in part relates to safe_mode, because safe_mode and KK>> a thread wrapper both do similar things here: safe_mode KK>> tries to simulate OS security mechanisms at user level KK>> in order to get a reuseable process and avoid forking KK>> new cgi interpreters each time. Threaded programs do KK>> the same (get a reuseable process), but with concurrent KK>> threads instead of serialized threads. That is, you can KK>> think of safe_mode as vfork()ed threads in some way... I see no point here. For solving thread problems (like virtualizing current directory so that it's different for every PHP thread, and making thread-local storage) there's TSRM module. Why safe_mode is needed is that all processes run by webserver (either threaded or not) are run under webserver user ID, and there's no way (at least until Apache 2.0 arrives) to change it. That's why we have safe_mode - to emulate behaviour that would be if the script was run under user ID of it's owner, and then adding some restrictions that might be needed because web-user access is lower-grade one from shell-access. KK>> context in a way we require, we would be using CGI php and KK>> have no need for safe_mode, because we would have no need KK>> for mod_php. For example, the operating system could provide Huh? CGI PHP is slow. Like _slooooooow_. It's new process every time. -- Stanislav Malyshev stas@zend.com http://www.zend.com/ +972-3-6139665 ext.106

« previous php.dev (#32547) next »