Re: [PHP4BETA] PHP 4.0b3 released
| From: | Stanislav Malyshev | Date: | Thu, 18 Nov 1999 13:47:55 +0000 |
| Subject: | Re: [PHP4BETA] PHP 4.0b3 released | ||
| Groups: | php.version4 | ||
| Request: | Send a blank email to php-version4+get-6441@lists.php.net to get a copy of this message | ||
>> Remember, this was a response to Mark's comments about setting up
>> shared libraries that _all_ VirtualHosts share.
That what I'm talking about - you can have several httpd's (each with
one's own VirtualHosts), and serveral setups. And none of them can be
controlled by root. In fact, the "root" user notion, as a
jack-of-all-trades, is rather unsuccessful. You really need no superuser
access to be able to install a PHP library. And it shouldn't be linked to
any particular user.
In fact, you are proposing to make shared library directory and make PHP
guess that the file is indeed a legal shared library by it's owner. I
propose to say just what you mean - that you want this directory to be
shared library directory, and let permissions and owners to go their way.
To make a long story short - the difference between my scheme and your
scheme is that you propose to identify which files user may require by
owner of these files, while I propose much more flexible method - by
location (or locations) of these files. My scheme fully contains yours -
if you make that dir root-owned (one simple chown -R), you
get exactly the same. But in my way you can get a number of those
directories, and control who has access to them in a way it was designed
in the OS, not making everything shared root-owned. root has too much
things on it already, anyway.
And the last point - with UID approach PHP now should remember both UID of
the owner of the currently parsed script and UID of the owner of the
original script - or you will instantly get access to all root-owned
files. I imagine this would be harder to implement than the notion of
"system library".
--
Stanislav Malyshev Zend Technologies Ltd.
stas@zend.com http://www.zend.com/
050-624945