[PHP-DEV] [PATCH] bug #29336

2004-07-25 Thread Antony Dovgal
Hi all! Plz, take a look at bug #29336 ( http://bugs.php.net/29336 for lazy ones =)). HEAD segfaults on session_start() after empty_string -> STR_EMPTY_ALLOC() change. This happens because SID constant gets initialized with "" string instead of STR_EMPTY_ALLOC(). The patch: http://tony2004.phpcl

Re: [PHP-DEV] Fwd: 5.0.1 and HTTP_AUTH

2004-07-25 Thread Olivier Hill
Andi Gutmans wrote: I'd like to roll 5.0.1 soon. I think the AUTH bug is biting a lot of people. Does anyone have any important fixes they want to commit to the PHP_5_0 branch before I roll it? Andi If libmysql is not bundled by default and no other extension throws this error, maybe this shoul

Re: [PHP-DEV] Fwd: 5.0.1 and HTTP_AUTH

2004-07-25 Thread Philip Olson
> I'd like to roll 5.0.1 soon. I think the AUTH bug is biting a lot of people. > Does anyone have any important fixes they want to commit to the PHP_5_0 > branch before I roll it? Some Windows users are still wondering about MySQL and the php-src/win32/install.txt has yet to be updated on the iss

[PHP-DEV] Fwd: 5.0.1 and HTTP_AUTH

2004-07-25 Thread Andi Gutmans
I'd like to roll 5.0.1 soon. I think the AUTH bug is biting a lot of people. Does anyone have any important fixes they want to commit to the PHP_5_0 branch before I roll it? Andi Subject: 5.0.1 and HTTP_AUTH Date: Sun, 25 Jul 2004 23:31:25 +0100 http://bugs.php.net/bug.php?id=29132 Yeah, they no

[PHP-DEV] Re: [PHP-CVS] cvs: php-src /ext/dom php_dom.c

2004-07-25 Thread Marcus Boerger
Hello internals, wez also uses this in com_dotnet so this may become a standard habit. Should i provide a standard implementation for it? regrads marcus Sunday, July 25, 2004, 8:50:26 PM, you wrote: > helly Sun Jul 25 14:50:26 2004 EDT > Modified files: > /php-src

Re: [PHP-DEV] Everyone on the road?

2004-07-25 Thread Rasmus Lerdorf
On Sun, 25 Jul 2004, Andi Gutmans wrote: > I think it's going to be quite hard and not really worthwhile to add > support for partial realpath(). In this case I like the kiss approach. It > gives a great bang for the buck and is very simple. Well, there is another approach here. There are only

Re: [PHP-DEV] Everyone on the road?

2004-07-25 Thread Andi Gutmans
Hi, Thanks for the in-depth analysis. I agree that we should nuke that extra fstat(). We need to track down where it is (probably streams :). I don't think it's a good idea to cache the stat() itself because usually you don't stat() the same file twice in the same request, and caching those in b

Re: [PHP-DEV] realpath benchmarks

2004-07-25 Thread Gareth Ardron
On Sun, 2004-07-25 at 12:53, Gareth Ardron wrote: > OK, very very quick benchmark on the realpath stuff Just as a bit of a follow-on.. > * after realpath modifications > [EMAIL PROTECTED]:/# time php /home/gaz/test.php > real3m12.067s > user1m22.602s > sys 1m24.608s The above was

Re: [PHP-DEV] Everyone on the road?

2004-07-25 Thread Andi Gutmans
At 06:30 PM 7/24/2004 +0200, Christian Schneider wrote: And to understand the security impact: include "./foo/bar/template_".$userinput; ... which I'd consider bad practice anyway but that's another story :-) Yep. That person deserves to have his site hacked :) Andi -- PHP Internals - PHP Runtime D

Re: [PHP-DEV] [PATCH] tests/classes/factory_and_singleton_010.phpt

2004-07-25 Thread Marcus Boerger
Hello Kamesh, Saturday, July 24, 2004, 6:10:56 PM, you wrote: > Hello Marcus, > On Thu, 22 Jul 2004 20:47:31 +0200, "Marcus Boerger" <[EMAIL PROTECTED]> > said: >> Hello Kamesh, >> >> can you adapt you test files to ouput a single line before the actual >> script starts by using 'echo "*\n";' f

Re: [PHP-DEV] Bugreports - is it worth it? (or: glob() disclosing file names with open_basedir and safe_mode-restriction)

2004-07-25 Thread Peter Brodersen
Hi, On Sun, 25 Jul 2004 11:12:26 -0400 (EDT) Adam Maccabee Trachtenberg <[EMAIL PROTECTED]> wrote: > > If nobody wants to give an answer to the above, my question would still be: > > Is there any way restricting people from retrieving file names (where > > open_basedir and safe_mode obviously won

Re: [PHP-DEV] Bugreports - is it worth it? (or: glob() disclosing file names with open_basedir and safe_mode-restriction)

2004-07-25 Thread George Schlossnagle
On Jul 25, 2004, at 11:12 AM, Adam Maccabee Trachtenberg wrote: On Sun, 25 Jul 2004, Peter Brodersen wrote: If nobody wants to give an answer to the above, my question would still be: Is there any way restricting people from retrieving file names (where open_basedir and safe_mode obviously won't h

Re: [PHP-DEV] Bugreports - is it worth it? (or: glob() disclosing file names with open_basedir and safe_mode-restriction)

2004-07-25 Thread Adam Maccabee Trachtenberg
On Sun, 25 Jul 2004, Peter Brodersen wrote: > If nobody wants to give an answer to the above, my question would still be: > Is there any way restricting people from retrieving file names (where > open_basedir and safe_mode obviously won't help), besides adding glob to > disable_functions in php.in

[PHP-DEV] Bugreports - is it worth it? (or: glob() disclosing file names with open_basedir and safe_mode-restriction)

2004-07-25 Thread Peter Brodersen
Hi, I have earlier posted my concern about some security issues, that has been dismissed, as mentioned in: http://news.php.net/php.internals/10849 Even though I still hope that my basic questions (as mentioned in the bottom of above post - reposted at the bottom of this post) would be answered, I

[PHP-DEV] realpath benchmarks

2004-07-25 Thread Gareth Ardron
OK, very very quick benchmark on the realpath stuff System used is an AMD Opteron 142 (1.6ghz) with a gig of pc2100 ram, and Western Digital Raptor sata disk. It's running Debian/unstable, though only in 32bit mode atm. Both tests were run using the standard php5 release rather than current CVS.

[PHP-DEV] [Fwd: PHP 5 installer]

2004-07-25 Thread Gabor Hojtsy
Forwarded. :) Goba --- Begin Message --- I would like to know if will be released a windows installer package of the php 5 version. Thanks in advance. Reinaldo Melo Filho from Brazil. -- Use o melhor sistema de busca da Internet Radar UOL - http://www.ra

[PHP-DEV] [Fwd: PHP5 in Windows]

2004-07-25 Thread Gabor Hojtsy
Forwarded. Goba --- Begin Message --- Why is there not an InstallShield Wizard? Will there be one? --- End Message --- -- PHP Internals - PHP Runtime Development Mailing List To unsubscribe, visit: http://www.php.net/unsub.php