ini system patch

From: Date: Thu, 02 Aug 2007 00:47:58 +0000
Subject: ini system patch
Groups: php.internals 
Request: Send a blank email to internals+get-31359@lists.php.net to get a copy of this message
Hi! The attached patch implements the following improvement in Apache module configuration handling: New INI stage is introduced - ZEND_INI_STAGE_HTACCESS and values set in .htaccess are passed to handlers with ZEND_INI_STAGE_HTACCESS instead of ZEND_INI_STAGE_ACTIVATE. The reason for this is that there are values - one of them being session.save_handler - that we want to allow administrator to set to arbitrary values, even not inside open_basedir/safe_mode restrictions, while we do want user-set values to be inside limits. The problem was that right now there's no way to see if the value is set from httpd.conf (admin) or from .htaccess (frequently user-accessible and user-writable). This patch enables to make such distinction. I don't see any modules depending on ZEND_INI_STAGE_ACTIVATE but if there would be they can easily be fixed to work with ZEND_INI_STAGE_HTACCESS too. The attached patch is for apache2 SAPI only, but same one would be needed for apache1 API. This patch will allow proper fix for CVE-2007-3378 (current one breaks BC). Comments/objections? -- Stanislav Malyshev, Zend Software Architect stas@zend.com http://www.zend.com/ (408)253-8829 MSN: stas@zend.com

« previous php.internals (#31359) next »