Re: [PHP4BETA] PHP 4.0b3 released

From: Date: Fri, 19 Nov 1999 04:40:10 +0000
Subject: Re: [PHP4BETA] PHP 4.0b3 released
Groups: php.version4 
Request: Send a blank email to php-version4+get-6435@lists.php.net to get a copy of this message
Addressed to: Stanislav Malyshev <stas@zend.com> php4beta@lists.php.net ** Reply to note from Stanislav Malyshev <stas@zend.com> Thu, 18 Nov 1999 10:55:33 +0200 (IST) > > >> What I want is: > >> > >> if( ( fileowner( ThisScript ) == fileowner( TargetFile )) OR # Existing check > >> ( fileowner( TargetFile ) == 'root' AND # Owned by root > >> !(fileperms( TargetFile ) && octdec('003') AND # Not > >> group/world writable* > >> fileowner( TargetDir ) == 'root' AND # Dir owned by root > >> !(fileperms( TargetDir ) && octdec('002') # Not > >> group/world writable > >> )) { # OK To act > > This doesn't sound good. Remember, this was a response to Mark's comments about setting up shared libraries that _all_ VirtualHosts share. > >>> This is not true when using virtual hosting for 100s, maybe 1000s, of > >>> clients on a single server. The nightmare of trying to update and > >>> _maintain_ so many versions of PHPLIB is the reason I won't use it. I think a _system wide_ shared library would be an asset to PHP. I have a couple of libraries I want to make available to all the virtualvhosts on my machine without turning off safe mode, and I hope to make quite a few more. I think the same thing for data files would be good too, but I could live without it. If the PHP community had a shared library available you would soon see a collection of utilities like the Perl module library. > First, you not always are giving root to a site webmaster > (and on virtual server setup - I mean real full-blown virtualized hosting - you > *never* do this). No, I do not want to give root to ANY of my webmasters. The files I am thinking of are libraries with common functions I want to make available to ALL the webmasters on a machine. No one but the system administrator gets to add or modify them, but anyone can read or execute them. They could include things like a page hit counter, a random image selector, a form-mail processor. You know, all the trivial tasks you don't want to have to create another copy of every time someone needs to use them. > Second, it seems too much trouble to administer. I think this would be a very easy way to provide shared libraries. No new configuration options are needed. (Maybe just one, to turn it of and off.) Once safe mode has been modified it works like this: One time when you set up the server: o Login as root o Create a directory for shared libraries, then chmod 766, chown root:root. o Add that directory to include_path o Restart the web server In this directory only I can install files, but every webmaster on my system can execute them, with safe mode on, no matter who owns the running script. To add a new function: o Write it o Place it in the system library directory, chmod 644, chown root:root. All the webmasters on the system can now share this code. > Why don't just make configurable admin parameter lib_dir, which can be set by > sysadmin and will tell PHP that it's safe to include/require (but not read or > otherwise access) files in that directory? This could, however, constitute > problem for those modules who actually read files (templates). Maybe there > shold be execute-only and read-and-execute (if you can read, you can execute > anyway) library dirs? -- That seems more complicated, and harder to implement to me. I don't care how it happens, I just want to see some kind of system wide shared library that anyone can use with safe mode on. I want very tight control over who can add files to the library, which is why I suggest it must be done by root. Maybe you should be able to select some other user in php.ini, but I look at maintaining this library to be similar to installing the web server, not something for an ordinary webmaster. If we're lucky, someday there will be a couple hundred standard libraries that almost everyone has on thier systems. If _anyone_ has ideas on this, I'd like to hear them. Rick

« previous php.version4 (#6435) next »