note 42380 rejected from security.apache by vincent
| From: | vincent@php.net | Date: | Fri, 14 May 2004 08:34:45 +0000 |
| Subject: | note 42380 rejected from security.apache by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-69598@lists.php.net to get a copy of this message | ||
Note Submitter: danm@prime.gushi.org
----
What needs to happen, realistically, is that all the functions that normally have their behavior
changed by safe_mode to do UID/GID checks, should use a suexec-like "wrapper" application
(which does the same sorts of checks that suexec does on caller, uid, etc) that will open the
filehandle for them with their UID. Rather than PHP having to check the permissions like safe mode
does, the job would be given back to the OS where it belongs.
This way, you still get the benefit of fast startup, because PHP remains a module (and the wrapper
application is small enough to load fast).
Of course, this has its dangerous side too, so it would be the type of thing that would be off-by
default unless the user had passed all the necessary options to ./configure, like suexec.