Re: [PHP4BETA] PHP 4.0b3 released
| From: | rwidmer at developersdesk dot com | Date: | Tue, 23 Nov 1999 20:30:32 +0000 |
| Subject: | Re: [PHP4BETA] PHP 4.0b3 released | ||
| Groups: | php.version4 | ||
| Request: | Send a blank email to php-version4+get-6718@lists.php.net to get a copy of this message | ||
Addressed to: Stanislav Malyshev <stas@zend.com>
php4beta@lists.php.net
** Reply to note from Stanislav Malyshev <stas@zend.com> Thu, 18 Nov 1999 15:47:55 +0200 (IST)
> In fact, the "root" user notion, as a
> jack-of-all-trades, is rather unsuccessful. You really need no
> superuser access to be able to install a PHP library. And it
> shouldn't be linked to any particular user.
>
I STRONGLY disagree. The root user is alive and well on every multi
user system I know of, and I don't see it going away any time soon.
Any time someone owns an expensive system and allows others to use it I
expect them to want final say on its operation. I certainly dont want
every email account to be able to install operating system patches, and
I consider the system wide shared PHP library to be almost as
sensitive.
Imagine the damage if someone 'upgrades' your global phplib so the
database abstraction layer emails everything that looks like a credit
card transaction to them. How do you tell 100 customers that all thier
transactions for the last month have been compromised? I want tight
control over who can update the shared PHP library, and root is the
tightest control I know of on unix.
> In fact, you are proposing to make shared library directory and make
> PHP guess that the file is indeed a legal shared library by it's
> owner. I propose to say just what you mean - that you want this
> directory to be shared library directory, and let permissions and
> owners to go their way.
The way I would state it is: "I propose that any file owned by root,
and only writable by root is safe to open when safe mode is on, no
matter who owns the script that is running." Any directory in the
existing include_path is a potential shared library directory,
depending on ownership.
>
> To make a long story short - the difference between my scheme and
> your scheme is that you propose to identify which files user may
> require by owner of these files, while I propose much more flexible
> method - by location (or locations) of these files. My scheme fully
> contains yours - if you make that dir root-owned (one simple chown
> -R), you get exactly the same. But in my way you can get a number of
> those directories, and control who has access to them in a way it was
> designed in the OS, not making everything shared root-owned. root has
> too much things on it already, anyway.
One other difference, my scheme is probably less than 1000 characters
in length, and only affects the file safe_mode.c. I think just
extending the if at line 103 (PHP4B3 initial release) as noted in my
first message would do the job. If I was a C programmer or had more
time right now, I'd whip out a patch. If it hasn't happened by the
first of the year I'll probably try it.
If you want to follow OS design, the thing to do would probably be to
make safe mode respect group associations. That would allow a customer
with more than one domain to share code within his domains without
exposing any other customers to it.
To me that is overkill. The only shared library I care about is the one
I provide for my customers, and _I_ control. I can control it just
fine by requiring the system administrator to install it. (BTW, I _am_
the system administrator, which may affect my outlook. :)
This is not about the ability of my customers to load private copies of
library code for thier own use, they just follow the existing safe mode
restrictions. This request is for stuff the ISP provides for all
customers to share.
>
> And the last point - with UID approach PHP now should remember both
> UID of the owner of the currently parsed script and UID of the owner
> of the original script - or you will instantly get access to all
> root-owned files. I imagine this would be harder to implement than
> the notion of "system library".
>
No, I dont want to grant the files any super power other than skipping
over the Safe_Mode restriction that they must be owned by the same user
that owns the running script.
Library scripts can call other library scripts because the other
library scrupts are also owned by root, not because the calling script
is owned by root. They could also require files owned by the original
user because the file is owned by the same user as the script that
called the library, but they are kept out of other customer accounts
because the owner's name is different.
And you only have to change _one_ if.
Rick