Re: [PHP4BETA] PHP 4.0b3 released

From: Date: Tue, 23 Nov 1999 20:30:32 +0000
Subject: Re: [PHP4BETA] PHP 4.0b3 released
Groups: php.version4 
Request: Send a blank email to php-version4+get-6718@lists.php.net to get a copy of this message
Addressed to: Stanislav Malyshev <stas@zend.com> php4beta@lists.php.net ** Reply to note from Stanislav Malyshev <stas@zend.com> Thu, 18 Nov 1999 15:47:55 +0200 (IST) > In fact, the "root" user notion, as a > jack-of-all-trades, is rather unsuccessful. You really need no > superuser access to be able to install a PHP library. And it > shouldn't be linked to any particular user. > I STRONGLY disagree. The root user is alive and well on every multi user system I know of, and I don't see it going away any time soon. Any time someone owns an expensive system and allows others to use it I expect them to want final say on its operation. I certainly dont want every email account to be able to install operating system patches, and I consider the system wide shared PHP library to be almost as sensitive. Imagine the damage if someone 'upgrades' your global phplib so the database abstraction layer emails everything that looks like a credit card transaction to them. How do you tell 100 customers that all thier transactions for the last month have been compromised? I want tight control over who can update the shared PHP library, and root is the tightest control I know of on unix. > In fact, you are proposing to make shared library directory and make > PHP guess that the file is indeed a legal shared library by it's > owner. I propose to say just what you mean - that you want this > directory to be shared library directory, and let permissions and > owners to go their way. The way I would state it is: "I propose that any file owned by root, and only writable by root is safe to open when safe mode is on, no matter who owns the script that is running." Any directory in the existing include_path is a potential shared library directory, depending on ownership. > > To make a long story short - the difference between my scheme and > your scheme is that you propose to identify which files user may > require by owner of these files, while I propose much more flexible > method - by location (or locations) of these files. My scheme fully > contains yours - if you make that dir root-owned (one simple chown > -R), you get exactly the same. But in my way you can get a number of > those directories, and control who has access to them in a way it was > designed in the OS, not making everything shared root-owned. root has > too much things on it already, anyway. One other difference, my scheme is probably less than 1000 characters in length, and only affects the file safe_mode.c. I think just extending the if at line 103 (PHP4B3 initial release) as noted in my first message would do the job. If I was a C programmer or had more time right now, I'd whip out a patch. If it hasn't happened by the first of the year I'll probably try it. If you want to follow OS design, the thing to do would probably be to make safe mode respect group associations. That would allow a customer with more than one domain to share code within his domains without exposing any other customers to it. To me that is overkill. The only shared library I care about is the one I provide for my customers, and _I_ control. I can control it just fine by requiring the system administrator to install it. (BTW, I _am_ the system administrator, which may affect my outlook. :) This is not about the ability of my customers to load private copies of library code for thier own use, they just follow the existing safe mode restrictions. This request is for stuff the ISP provides for all customers to share. > > And the last point - with UID approach PHP now should remember both > UID of the owner of the currently parsed script and UID of the owner > of the original script - or you will instantly get access to all > root-owned files. I imagine this would be harder to implement than > the notion of "system library". > No, I dont want to grant the files any super power other than skipping over the Safe_Mode restriction that they must be owned by the same user that owns the running script. Library scripts can call other library scripts because the other library scrupts are also owned by root, not because the calling script is owned by root. They could also require files owned by the original user because the file is owned by the same user as the script that called the library, but they are kept out of other customer accounts because the owner's name is different. And you only have to change _one_ if. Rick

« previous php.version4 (#6718) next »