note 31589 rejected from features.safe-mode by didou
| From: | didou@php.net | Date: | Fri, 03 Oct 2003 16:38:40 +0000 |
| Subject: | note 31589 rejected from features.safe-mode by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-57758@lists.php.net to get a copy of this message | ||
Note Submitter: gk@proliberty.com
----
The documentation on safe_mode is wrong. It says:
>When safe_mode is on, PHP checks to see if the owner of the current script matches the owner of
>the file to be operated on by a file function.
In truth, it also checks the ownership of the current directory: directory ownership overrides file
UID - i.e., if you own the directory, your script can read any files in the directory, regardless of
file UID. Rasmus has confirmed that this is not a bug, it is by design. The documentation should be
updated to reflect this.