Yeah, the description they gave was confusing. At first I thought it
was an SAPI module that would somehow change the userid of the Apache
process handling the request to that of the owner of the php file. But
it looks to be a hardwired setuid CGI wrapper, as you said.