note 30422 deleted from features.file-upload by vincent

From: Date: Thu, 11 Sep 2003 12:27:49 +0000
Subject: note 30422 deleted from features.file-upload by vincent
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-56113@lists.php.net to get a copy of this message
Note Submitter: gm@NOSPAM.df.PLEASE.ru ---- Keywords: file upload problems The PHP Online Manual describes upload_tmp_dir as follows: "The temporary directory used for storing files when doing file upload. Must be writable by whatever user PHP is running as. If not specified PHP will use the system's default." and in "php.ini-recommended" file this variable is commented out to apply default behavior, but this is not works as you might expect. If we will look the source (main/php_open_temporary_file.c) at the get_temporary_dir() function, we will notice that for Windows platform detection of system temporary directory works properly, while for UNIX-like OSes it depends of the current value of TMPDIR environment variable. Imagine, that you started up your server and, after some uptime, decided to update your Apache binaries. Let's look on TMPDIR environment variable all the way we described above: 1. Starting up the system. The system init script will set correct value to the TMPDIR environment variable (usually, /tmp) 2. Starting up the Apache web server Apache environment will be cloned from the current one, which, at this moment, holds correct TMPDIR value 3. Logging as root user, shutting down Apache, doing a maintance works, starting up Apache again. This is the weakest place of described system temporary directory detection logic based on environment variable. Think, that OS is configured to provide separated temporary directories for each user (good strategy), or this user configured his system to store root's temporary directory in safe place which not intersects with other users (for example, in his home directory). So, TMPDIR for this user session will be "/root/tmp" (for example). After starting Apache, it's environment will be holding a copy of current TMPDIR. Next step, after binding to port, Apache drops it's privilegies of superuser and losts permisions to the directory pointed by TMPDIR. Oops, no file uploads possible. Resume: set the upload_tmp_dir to your system temporary directory by hand. Suggestion to PHP develompent team: maybe hardcoding "/tmp" as sane default is better way to get safe system temporary directory on UNIX-like OSes?

« previous php.notes (#56113) next »