PHP 4.0.3pl1 [CGI] + Apache 1.3.14 = trouble

From: Date: Fri, 24 Nov 2000 12:26:34 +0000
Subject: PHP 4.0.3pl1 [CGI] + Apache 1.3.14 = trouble
Groups: php.general 
Request: Send a blank email to php-general+get-26947@lists.php.net to get a copy of this message
[I hesitated between php-general and php-devel for this question, but decided on php-general. I hope that's ok.] Hi! I've been running a beta of PHP4 until today, when I got some time to download and compile 4.0.3pl1 (on Solaris) [more technical info at the end]. Much to my grief, it didn't work. I suspect there is a bug, or at least an unexpected behaviour, and I don't _think_ it's in my setup. But I thought I'd hear if anyone here knows what's going on before I submit it as a bug. In my setup, I run the CGI-version of PHP through and Apache 'AddHandler' directive. The problem is that the PHP-scripts aren't being run. After a bit of testing, I discovered what the problem is. Apache and PHP do _not_ agree on the meaning of the CGI-specific environment variable, the SCRIPT_FILENAME variable. Whereas PHP expects SCRIPT_FILENAME to point to the _PHP_script_ it's expected to execute, Apache actually points it to the _CGI_script_ it is executing, which is the PHP-parser (i.e. the program 'php'). Apache sets PATH_TRANSLATED to the path of the PHP script. Thus PHP regardless of input data always tries to execute its own binary as a PHP script (which of course fails miserably. :-) So what I wonder is: Is there a good reason for PHP attempting to extract the PHP script path from SCRIPT_FILENAME rather than PATH_TRANSLATED, which Apache actually sets? It seems to make the CGI-version useless under Apache handlers, which of course is bad for PHP. Is this a bug, or have I misunderstood something? A very short background on my setup: I run Apache 1.3.14 under Solaris on a relatively high-traffic student webserver at our university. We have about 2000 separate users. In order for them to run their PHP scripts under their own user- and group-ids (which is the only acceptable way), I use a setuid wrapper that runs the CGI-version of PHP (after extensible security checks :-). To make sure this wasn't a problem with my wrapper, I did a test setup that didn't use it: ScriptAlias /tmp-cgi-bin/ /www/pkg/php-4.0/bin/ Action php-script /tmp-cgi-bin/php AddHandler php-script .php The above is an example of a real setup, without the wrapper, that directly runs PHP and that manifests the problem. Accessing http://myserver/foo.php under this setup will give PHP the environment variables DOCUMENT_ROOT=/www/pub/dtek PATH_TRANSLATED=/www/pub/dtek/foo.php SCRIPT_FILENAME=/www/pkg/php-4.0/bin/env SCRIPT_NAME=/tmp-cgi-bin/env PHP uses SCRIPT_FILENAME, and even re-sets PATH_TRANSLATED to the value of SCRIPT_FILENAME, which is not what Apache means for it to use. /Viktor... --| Viktor Fougstedt, system administrator at dtek.chalmers.se |-- --| http://www.dtek.chalmers.se/~viktor/ |-- --| ...soon we'll be sliding down the razor blade of life. /Tom Lehrer |--

« previous php.general (#26947) next »