Re: patch - adds new setting safe_mode_hide_env_vars
| From: | Andi Gutmans | Date: | Sat, 21 Oct 2000 17:31:35 +0000 |
| Subject: | Re: patch - adds new setting safe_mode_hide_env_vars | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-35732@lists.php.net to get a copy of this message | ||
Oh, OK. In that case, it does sound reasonable.
I still would like to move some of the other safe_mode stuff (like checkuid()) to a more centralized place such as php_fopen_and_set_opened_path() (I moved open_basedir there) but there are some issues such as in the GD module where you do want to allow the developer to open certain files even if they aren't under his uid.
This whole safe_mode issue is a very complex issue and I don't know easily we can:
a) centralize it more
b) Make sure everything is safe_mode'ed and works the way it's supposed to.
Right now I tell people that I don't consider safe_mode as being completely "safe".
Andi
At 11:57 AM 10/21/00 -0500, Jason Greene wrote:
I did think of that, safe_mode blocks all capibility to execute commands ( backtics, passthru, exec, system, etc ) -Jason Andi Gutmans wrote: What if someone does exec("printenv") ? He can still get all of the environment variables. Andi At 04:35 PM 10/20/00 -0700, Jason Greene wrote:--- Andi Gutmans <andi@zend.com> http://www.zend.com/If you guys could take a look at this patch, and see what you think. This allows for an ini setting that will block specified environmental variables from being seen by php scripts. It does make one update that probably should be moved, and that is in php_module_startup. Since this uses a hashtable datatype, zend_hash_init needs to be called. You guys probably don't want this in the main startup, but I figured that you could let me know where it could go best. Maybe a startup call in safe_mode.c? I know we had discussions about doing an env -i before running apache, and I do agree on cleaning the apache users environment, but there is always the possibility of env vars you can't remove. (LD_LIBRARY_PATH) . If you like the idea, but want things in different places let me know -Jason -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net--- Andi Gutmans <andi@zend.com> http://www.zend.com/