PHP 4.0.3pl1 [CGI] + Apache 1.3.14 = trouble
| From: | Viktor Fougstedt | Date: | Fri, 24 Nov 2000 12:26:34 +0000 |
| Subject: | PHP 4.0.3pl1 [CGI] + Apache 1.3.14 = trouble | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-26947@lists.php.net to get a copy of this message | ||
[I hesitated between php-general and php-devel for this question, but
decided on php-general. I hope that's ok.]
Hi!
I've been running a beta of PHP4 until today, when I got some time to
download and compile 4.0.3pl1 (on Solaris) [more technical info at the
end].
Much to my grief, it didn't work. I suspect there is a bug, or at
least an unexpected behaviour, and I don't _think_ it's in my setup. But
I thought I'd hear if anyone here knows what's going on before I
submit it as a bug.
In my setup, I run the CGI-version of PHP through and Apache
'AddHandler' directive. The problem is that the PHP-scripts aren't
being run.
After a bit of testing, I discovered what the problem is. Apache and
PHP do _not_ agree on the meaning of the CGI-specific environment
variable, the SCRIPT_FILENAME variable.
Whereas PHP expects SCRIPT_FILENAME to point to the _PHP_script_ it's
expected to execute, Apache actually points it to the _CGI_script_ it
is executing, which is the PHP-parser (i.e. the program 'php'). Apache
sets PATH_TRANSLATED to the path of the PHP script.
Thus PHP regardless of input data always tries to execute its own
binary as a PHP script (which of course fails miserably. :-)
So what I wonder is: Is there a good reason for PHP attempting to
extract the PHP script path from SCRIPT_FILENAME rather than
PATH_TRANSLATED, which Apache actually sets?
It seems to make the CGI-version useless under Apache handlers, which
of course is bad for PHP.
Is this a bug, or have I misunderstood something?
A very short background on my setup:
I run Apache 1.3.14 under Solaris on a relatively high-traffic student
webserver at our university. We have about 2000 separate users. In
order for them to run their PHP scripts under their own user- and
group-ids (which is the only acceptable way), I use a setuid wrapper
that runs the CGI-version of PHP (after extensible security checks
:-).
To make sure this wasn't a problem with my wrapper, I did a test setup
that didn't use it:
ScriptAlias /tmp-cgi-bin/ /www/pkg/php-4.0/bin/
Action php-script /tmp-cgi-bin/php
AddHandler php-script .php
The above is an example of a real setup, without the wrapper, that
directly runs PHP and that manifests the problem. Accessing
http://myserver/foo.php
under this setup will give PHP the environment variables
DOCUMENT_ROOT=/www/pub/dtek
PATH_TRANSLATED=/www/pub/dtek/foo.php
SCRIPT_FILENAME=/www/pkg/php-4.0/bin/env
SCRIPT_NAME=/tmp-cgi-bin/env
PHP uses SCRIPT_FILENAME, and even re-sets PATH_TRANSLATED to the
value of SCRIPT_FILENAME, which is not what Apache means for it to
use.
/Viktor...
--| Viktor Fougstedt, system administrator at dtek.chalmers.se |--
--| http://www.dtek.chalmers.se/~viktor/
|--
--| ...soon we'll be sliding down the razor blade of life. /Tom Lehrer |--