Index: ext/curl/interface.c =================================================================== RCS file: /repository/php-src/ext/curl/interface.c,v retrieving revision 1.46.2.4 diff -u -r1.46.2.4 interface.c --- ext/curl/interface.c 18 Oct 2004 22:42:16 -0000 1.46.2.4 +++ ext/curl/interface.c 29 Oct 2004 08:14:30 -0000 @@ -773,12 +773,48 @@ WRONG_PARAM_COUNT; } + if (argc > 0) { + char *tmp; + int tmp_len; + + convert_to_string_ex(url); + + if (strncasecmp(Z_STRVAL_PP(url), "file:///",8) == 0) { + tmp_len = Z_STRLEN_PP(url) - 7; + + tmp = emalloc(tmp_len + 1); + memcpy(tmp, Z_STRVAL_PP(url) + 7, tmp_len); + tmp[tmp_len] = '\0'; + + if (php_check_open_basedir(tmp TSRMLS_CC) || (PG(safe_mode) && !php_checkuid(tmp, "rb+", CHECKUID_CHECK_MODE_PARAM))) { + efree(tmp); + RETURN_FALSE; + } + + efree(tmp); + } + else if (strncasecmp(Z_STRVAL_PP(url), "file://localhost/",17) == 0) { + tmp_len = Z_STRLEN_PP(url) - 16; + + tmp = emalloc(tmp_len + 1); + memcpy(tmp, Z_STRVAL_PP(url) + 16, tmp_len); + tmp[tmp_len] = '\0'; + + if (php_check_open_basedir(tmp TSRMLS_CC) || (PG(safe_mode) && !php_checkuid(tmp, "rb+", CHECKUID_CHECK_MODE_PARAM))) { + efree(tmp); + RETURN_FALSE; + } + + efree(tmp); + } + } + cp = curl_easy_init(); if (!cp) { php_error_docref(NULL TSRMLS_CC, E_WARNING, "Could not initialize a new cURL handle"); RETURN_FALSE; } - + alloc_curl_handle(&ch); TSRMLS_SET_CTX(ch->thread_ctx); @@ -808,7 +844,6 @@ if (argc > 0) { char *urlcopy; - convert_to_string_ex(url); urlcopy = estrndup(Z_STRVAL_PP(url), Z_STRLEN_PP(url)); curl_easy_setopt(ch->cp, CURLOPT_URL, urlcopy);