[patch] safe_mode_include_dir
| From: | James E. Flemer | Date: | Fri, 01 Feb 2002 18:31:22 +0000 |
| Subject: | [patch] safe_mode_include_dir | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-78787@lists.php.net to get a copy of this message | ||
Hello ... It's been a while since I've actively been
committing to PHP. So I thought I'd run this by everyone
first.
This is a patch to change the behavior of the PHP.INI
directive "safe_mode_include_dir" (which I added about 6
months ago). As it is currently, "safe_mode_include_dir"
takes a single directory (ie. /usr/local/lib/php) and
bypasses UID/GID checks on files included from that
directory.
This patch changes the behavior to allow a path-style list
of directories to be listed (similar to "include_path").
While I was at it, I made the code surrounding the check
much more readable by separating the safe_mode_include_dir
check into a separate function (a la open_base_dir_check).
Since a single directory is a valid path-style string, this
patch is completely backward compatible. Unless I broke
anything in the actual checking, which is another reason I
am posting this before I commit it. I cannot get current
CVS to build, so this patch is off of php-4.1.1, but
applies cleanly to php-cvs.
Thanks,
-James