Re: PHP6, drop open_basedir?
| From: | Stas Malyshev | Date: | Tue, 17 Jun 2014 20:32:25 +0000 |
| Subject: | Re: PHP6, drop open_basedir? | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-74957@lists.php.net to get a copy of this message | ||
Hi!
> On Windows f.e. it is very easy to create application pool with the
> right users/permissions settings (IIS) or only permissions settings
> (Apache). It is not possible to create one user per host on Apache
> using mod_php but I think it is acceptable as it is mostly used as
> development server or dedicated apps.
This is not exactly true. Setups running multiple apps on mod_php/Apache
are numerous.
That said, open_basedir is not really a security feature meant to stop
somebody with code execution access on the server. It's more of a
safeguard feature - i.e. if somebody forgets to add check to some fopen,
so that it may venture outside app space, open_basedir allows to
implement such checks on a certain group of functions. I think it is a
useful function, even though its framing in a security context makes it
look like it does something that it can not do. It's like filters - very
useful is some context but if you think you just slap a filter on your
insecure code and get security=On then you're mistaken.
So I don't think we need to remove this. I don't see a lot of
maintenance problem with it as long as we use streams properly (and we
should anyway) and we make it very clear what this tool actually does.
--
Stanislav Malyshev, Software Architect
SugarCRM: http://www.sugarcrm.com/
(408)454-6900 ext. 227