Re: How safe is PHP?

From: Date: Sat, 11 Aug 2001 12:18:38 +0000
Subject: Re: How safe is PHP?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-62935@lists.php.net to get a copy of this message
At 00:21 03-05-01, Nick Loman wrote:
After having these crashes which I think were due to file upload (but who knows!) recently, I've been mulling the question: how safe is PHP? Namely how effective is the memory_limit directive? Forgive me because I don't know enough about PHP's architecture but is this memory_limit directive an absolute? Is there absolutely positively no way a child process can use more than memory_limit? Or are there situations where it can be exceeded, e.g. can certain bugs in PHP modules cause it to be ignored?
memory_limit is not absolute. It applies only to memory allocated through the Zend memory manager. In particular, this does not include: - Some initial memory size taken by the process - Memory allocated in 3rd party library. E.g., a MySQL result set. That's quite common, and greatly depends on what you're doing. - Memory allocated in modules, not through the memory manager. That's typically a bug, and is not very common. Note, that memory_limit is not enforced by default. You have to build PHP with --enable-memory-limit in order to support it. Zeev

« previous php.dev (#62935) next »