Re: chroot(): _not_ safe-mode restricted?

From: Date: Mon, 20 Aug 2001 19:27:32 +0000
Subject: Re: chroot(): _not_ safe-mode restricted?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-63902@lists.php.net to get a copy of this message
On Mon, 20 Aug 2001, Jeroen van Wolffelaar wrote: > > > As I read it in CVS, chroot() will work even in safe-mode. Isn't this a > > > bad idea(tm), or am I wrong? > > > If users can chroot in safe-mode, Apache won't serve any more pages > > > after all children have been chrooted to an empty dir? > > > > uhm, where have you read that? [ curious ] > > > I just reasoned what could happen. if you chroot a child, I couldn't see a > reason why it'd get respawned (since it doesn't die), but it will become a > useless child, I guessed. It will be useless indeed, as the filesystem root of it has been changed then. > > > nope, cause it will run as apache user, and you have to be root to > > chroot(). > > I believe there are webservers which are run as root, or not? If that is the > case, chroot should be disabled in safe-mode IMHO, or better, disabled in > webserver envirment. If your sysadm runs a webserver as root, you should fire him IMO. > > Currently the docs say that it is not *wise* to use it in webserver-env, not > that is impossible. That's why I questioned safe-mode restrictions here. yeah, right... I think it should only work in plain CGI mode, with no CGI things in it (force-cgi-redirect) or other stuff. It simply has no use in this cases... Derick

« previous php.dev (#63902) next »