note 42380 added to security.apache
| From: | danm at prime dot gushi dot org | Date: | Fri, 14 May 2004 02:43:22 +0000 |
| Subject: | note 42380 added to security.apache | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-69592@lists.php.net to get a copy of this message | ||
What needs to happen, realistically, is that all the functions that normally have their behavior
changed by safe_mode to do UID/GID checks, should use a suexec-like "wrapper" application
(which does the same sorts of checks that suexec does on caller, uid, etc) that will open the
filehandle for them with their UID. Rather than PHP having to check the permissions like safe mode
does, the job would be given back to the OS where it belongs.
This way, you still get the benefit of fast startup, because PHP remains a module (and the wrapper
application is small enough to load fast).
Of course, this has its dangerous side too, so it would be the type of thing that would be off-by
default unless the user had passed all the necessary options to ./configure, like suexec.
----
Manual Page -- http://www.php.net/manual/en/security.apache.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+42380
Delete -- http://master.php.net/manage/user-notes.php?action=delete+42380&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+42380&report=yes
Search -- http://master.php.net/manage/user-notes.php