Re: [PHP4BETA] PHP 4.0b3 released
| From: | rwidmer at developersdesk dot com | Date: | Mon, 29 Nov 1999 21:29:39 +0000 |
| Subject: | Re: [PHP4BETA] PHP 4.0b3 released | ||
| Groups: | php.version4 | ||
| Request: | Send a blank email to php-version4+get-7015@lists.php.net to get a copy of this message | ||
Addressed to: Joey Smith <joey@samaritan.com>
php4beta@lists.php.net
** Reply to note from Joey Smith <joey@samaritan.com> Wed, 24 Nov 1999 08:25:24 -0700
(Mountain Standard Time)
>
> I really don't understand what makes you think root user has any
> tighter control than user foo. The unix model, at least, provides
> equally tight security irrelevant of who you are...
>
>
My choice of the root user is based on the simplicity of the patch to
php. A couple more checks at a single _if_ in safe_mode.c and everyone
on a system can share common code. No changes to php configuration, I
don't even have to lookup the uid, I already know it is 0. The
secuiity model "if root wrote it, it is safe" sounds reasonable to me.
Having to be root to update the system library may be a little bit of a
hassle, but I think most people are already root when they are
installing php so moving the files into the library then shouldn't be
a big problem.
I'd love to have a new path in php that lets anyone execute php code,
and safe mode respect for group membership, but those are big projects
that should not hold up the release of php4. I don't even know where
to start on projects like that. (Probably a week or a month of study on
the php source code, but ... )
I have quite a bit of common code I want to share across many virtual
domains without having to have a separate copy for each one. This
looks like a simple, effective way to do it. Unless someone beats me
to it, I'll add it to my copy of php4b3 and see what happens right
after I finish the two rush jobs alredy on my list. If it works like I
expect, I'll publish a patch and some examples on how to use it.
Rick