ini system patch
| From: | Stanislav Malyshev | Date: | Thu, 02 Aug 2007 00:47:58 +0000 |
| Subject: | ini system patch | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-31359@lists.php.net to get a copy of this message | ||
Hi!
The attached patch implements the following improvement in Apache module
configuration handling:
New INI stage is introduced - ZEND_INI_STAGE_HTACCESS and values set in
.htaccess are passed to handlers with ZEND_INI_STAGE_HTACCESS instead of
ZEND_INI_STAGE_ACTIVATE.
The reason for this is that there are values - one of them being
session.save_handler - that we want to allow administrator to set to
arbitrary values, even not inside open_basedir/safe_mode restrictions,
while we do want user-set values to be inside limits. The problem was
that right now there's no way to see if the value is set from httpd.conf
(admin) or from .htaccess (frequently user-accessible and
user-writable). This patch enables to make such distinction.
I don't see any modules depending on ZEND_INI_STAGE_ACTIVATE but if
there would be they can easily be fixed to work with
ZEND_INI_STAGE_HTACCESS too. The attached patch is for apache2 SAPI
only, but same one would be needed for apache1 API.
This patch will allow proper fix for CVE-2007-3378 (current one breaks BC).
Comments/objections?
--
Stanislav Malyshev, Zend Software Architect
stas@zend.com http://www.zend.com/
(408)253-8829 MSN: stas@zend.com