Re: [PHP4BETA] PHP 4.0b3 released

From: Date: Thu, 18 Nov 1999 14:17:54 +0000
Subject: Re: [PHP4BETA] PHP 4.0b3 released
Groups: php.version4 
Request: Send a blank email to php-version4+get-6395@lists.php.net to get a copy of this message
** Reply to note from Mark Constable <markc@renta.net> Wed, 17 Nov 1999 18:22:00 +0000 > > Eric McKeown wrote: > > On Wed, 17 Nov 1999, Randy Jay Yarger wrote: > > > There is a lot to be said for abstraction. There is also alot to be said > > > for having abstraction in the core as writing 'pure core' PHP makes it > > > trivial to move to another PHP-aware system. Using PHPLIB limits you to > > > systems with PHPLIB installed. > > > > True, but installation of PHPLIB is trivial. Any user responsible for the > > maintenance of a document hierarchy can install PHPLIB for use with that > > hierarchy, since PHPLIB is just a set of PHP scripts. Installation of > > PHPLIB is really not that daunting; any user with access to a PHP > > interpreter and a SQL backend should be able to install and use it. > > This is not true when using virtual hosting for 100s, maybe 1000s, of clients on a > single server. The nightmare of trying to update and _maintain_ so many versions of > PHPLIB is the reason I won't use it. > What about a way to install library code that all php users can share? Seems to me that it wouldn't take much more than allowing any file owned by root, only writable by root, and in a directory only writable by root to be fopen( '', 'r' )'ed, include()d, require()d, etc by anyone when safe mode is on. You probably want to do this for both executable scripts and data files. Things like a list of states, or credit card types in a common file might be handy to have available for all virtual hosts. That single hole in the existing safe mode with a little discepline when writing common library code would make shared php modules easy to setup for the system administrator, while keeping control of the shared code tightly controlled on the system. <WARNING: I'M NOT a C programmer, and have not looked at the PHP source code.> I think you already have the ownership info for the file available from the stat safe mode does to get the userid of the file. You might have to stat the parent directory to make sure it is not writable by anyone but root. I think safe mode is something like: if( fileowner( ThisScript ) = fileowner( TargetFile )) { # OK To act What I want is: if( ( fileowner( ThisScript ) == fileowner( TargetFile )) OR # Existing check ( fileowner( TargetFile ) == 'root' AND # Owned by root !(fileperms( TargetFile ) && octdec('003') AND # Not group/world writable* fileowner( TargetDir ) == 'root' AND # Dir owned by root !(fileperms( TargetDir ) && octdec('002') # Not group/world writable )) { # OK To act * I'm not sure if I want to use 003, 033 or 0113 on file permissions test. I see no reason for any php library to be executable so 0111 should probably be in it. I think it is best to allow the group to write the file too. Root will just have to be careful who is in the group when creating common library files. </WARNING> Rick

« previous php.version4 (#6395) next »