Re: Re: PEAR in safe_mode
| From: | Tomas V.V.Cox | Date: | Thu, 19 Jul 2001 10:27:40 +0000 |
| Subject: | Re: Re: PEAR in safe_mode | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-885@lists.php.net to get a copy of this message | ||
Martin Jansen wrote:
>
> On Thu, 19 Jul 2001 12:07:44 +0200 (MEST), Luc Saint-Elie wrote:
>
> >Perhaps I donºt understand clearly your problem (Iºm French, English
> >is not my native language), but what I meant is that I donºt use a ISP
> >provided PEAR install.
>
> But that's what we want to do: We want to provide a central PEAR
> installation for all virtual hosts on the server and use safe mode
> at the same time (due to the administrator's security paranoia).
The administrator security paranoia is the only thing than can safe your
private data and honor from the predator hackers :)
> >Included in my ISP account is a « include » directory. This « include »
> >directory is inside my account root.
> >I get PEAR files via CVS, and throw them in my include dir.
>
> Yes, that is a possibility we also thought of. But: We have a lot of
> projects, that use PEAR DB and having a local version of PEAR for each
> project may end up in a big mess when updating PEAR.
>
> Does anyone else has a solution for this problem?
Use appropiate file perms is the only needed thing (chown apache:apache
-R <..>/pear/). The classes that need run external programs won't run if
safe_mode_exec_dir is set and these external programas aren't in this
safe exec dir (examples are Mail_sendmail, pear installer, etc). Other
different thing is for example if the admin had disabled some functions
(like sockets, file opens, ini_set) that would disturb some classes.
Please let me know where you have problems after setting the correct
perms.
Tomas V.V.Cox