note 31589 added to features.safe-mode
| From: | gk at proliberty dot com | Date: | Sun, 27 Apr 2003 07:05:19 +0000 |
| Subject: | note 31589 added to features.safe-mode | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-47163@lists.php.net to get a copy of this message | ||
The documentation on safe_mode is wrong. It says:
>When safe_mode is on, PHP checks to see if the owner of the current script matches the owner of
>the file to be operated on by a file function.
In truth, it also checks the ownership of the current directory: directory ownership overrides file
UID - i.e., if you own the directory, your script can read any files in the directory, regardless of
file UID. Rasmus has confirmed that this is not a bug, it is by design. The documentation should be
updated to reflect this.
--
http://www.php.net/manual/en/features.safe-mode.php
http://master.php.net/manage/user-notes.php?action=edit+31589
http://master.php.net/manage/user-notes.php?action=delete+31589
http://master.php.net/manage/user-notes.php?action=reject+31589