Re: Hold 4.2.1

From: Date: Mon, 13 May 2002 09:43:48 +0000
Subject: Re: Hold 4.2.1
References: 1  Groups: php.qa 
Request: Send a blank email to php-qa+get-5401@lists.php.net to get a copy of this message
I tend to agree with Derick. It won't be the first and certainly won't be the last bug in safe mode that allows users to defeat the file permission protection - ISPs can disable ini_set easily if they wish. I'll implement a way to deny specific INI entries from being modified by users for 4.3.0. 4.2.0 came out with some VERY serious bugs, and we need 4.2.1 to come out yesterday. Zeev At 10:20 13/05/2002, Derick Rethans wrote:
Hello, On Sun, 12 May 2002, Rasmus Lerdorf wrote: I think we have to hold 4.2.1 until we put in a fix for the ini_set() problem. See bugs.php.net/17169 open_basedir would work here, wouldn't it? A trivial fix would of course be to just not allow ini_set() from safe-mode and perhaps also block .htaccess sets. And maybe that should be the quickfix for 4.2.1 and do something a bit more advanced for 4.3 like perform the checkuid and open_basedir checks on the ini_set arguments appropriately. I'll attack this in the morning after I get some sleep unless somebody else wants to dive in. I really think it's a bad idea to do trivial hacks. And changing ini_set() like this may affect a lot of users, as they might be using it already in safe_mode installations. Something I wouldn't want in a bugfix release. I'd rather go for a thourough check for 4.3, and release 4.2.1 just on schedule. (I don't want to postpone it another two weeks for RCs as the number of bugs that are now fixed withheld ISPs from upgrading to 4.2.x). regards, Derick ---------------------------------------------------------------------------
 Derick Rethans                             http://www.jdimedia.nl/derick/
 JDI Media Solutions                               http://www.jdimedia.nl/
---------------------------------------------------------------------------


« previous php.qa (#5401) next »