#32286 [Opn->Csd]: "safe-mode" needs some better docs..
| From: | vrana@php.net | Date: | Thu, 21 Apr 2005 10:23:05 +0000 |
| Subject: | #32286 [Opn->Csd]: "safe-mode" needs some better docs.. | ||
| References: | 1 | Groups: | php.doc |
| Request: | Send a blank email to phpdoc+get-969367944@lists.php.net to get a copy of this message | ||
ID: 32286
Updated by: vrana@php.net
Reported By: joe dot knall at gmx dot net
-Status: Open
+Status: Closed
Bug Type: Documentation problem
Operating System: Linux
PHP Version: 4.3.10
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
"This function returns FALSE for files inaccessible due to safe mode
retrictions. However these files still can be included if they are
located in safe_mode_include_dir."
Previous Comments:
------------------------------------------------------------------------
[2005-04-14 00:23:51] joe dot knall at gmx dot net
By the way, shouldn't it better be impossible to include a file that
doesn't exist? I consider it rather a bug than a docu problem.
------------------------------------------------------------------------
[2005-04-14 00:06:07] joe dot knall at gmx dot net
Apparently there was nothing deleted;
as stated this issue is closed for me, sniper switched it to
"Documentation problem".
The actual problem was/is:
it's irritating and not logical from the user's point of
view that when save_mode=ON file_exists($file) returns FALSE if $file
is not owned by the user who owns the script that executs
file_exists($file) - but at the same time $file can be used with
include/require. This is not clear from the docs.
I added a comment to the user contributed notes at file_exists()
saying
"if safe_mode=ON and $file (in safe_mode_include_dir) is not owned by
the user who executes file_exists($file), file_exists returns FALSE but
still $file can be included;
I could handle this by setting safe_mode_gid=On and appropriate
group-ownership"
... and would appreciate a hint like this as part of the official
documentation.
That's all, thank you
------------------------------------------------------------------------
[2005-04-06 08:43:01] philip@php.net
Looks like some comments got deleted...what was the problem and what do
you feel needs documented exactly?
------------------------------------------------------------------------
[2005-03-15 23:53:18] joe dot knall at gmx dot net
> ownership doesn't matter;
ownership does matter!
if /php/lib/php/file.php is owned by webmaster:webmaster it works,
otherwise the result is as stated;
THANK YOU, I'm sorry; I mixed it up during all the testing somehow:(
but still it's irritating and not logical from the user's point of
view;
in my special case (Smarty, in /php/lib/php/Smarty) the files are owned
by root:root; ok, this could be handled with the safe_mode_gid option
and setting those file's ownership to root:webmaster (as far as I
understand by now) ...
still I think, if a file can be included it should exist;
for me this case is closed by now; if you think this behaviour with
safe mode is as intended please set the status to closed and
_add_a_sentence_to_the_docu_
thank you
------------------------------------------------------------------------
[2005-03-14 01:17:42] sniper@php.net
As what user you run that script? And what does this output:
# ls -l /php/lib/php/file.php
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/32286
--
Edit this bug report at http://bugs.php.net/?id=32286&edit=1