#47930 [Asn]: ext/filter crashes when module startup bails out
| From: | pajoye@php.net | Date: | Sat, 05 Sep 2009 17:17:31 +0000 |
| Subject: | #47930 [Asn]: ext/filter crashes when module startup bails out | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-142005@lists.php.net to get a copy of this message | ||
ID: 47930
Updated by: pajoye@php.net
Reported By: stas at zend dot com
Status: Assigned
Bug Type: Reproducible crash
Operating System: *
PHP Version: 5.2CVS-2009-04-29
-Assigned To: derick
+Assigned To: stas
New Comment:
Any reason why this change has been commited to HEAD but never to 5.3,
or has it been reverted?
Please clarify the situation and sync both branches as soon as
possible.
Previous Comments:
------------------------------------------------------------------------
[2009-04-29 00:41:24] stas@php.net
fixed for 5.3/HEAD, 5.2 fix still required, since 5.3+ fix changes
binary API
------------------------------------------------------------------------
[2009-04-08 23:01:04] stas at zend dot com
Description:
------------
1. If one of the modules startup bails out, that leads to aborting the
startup sequence and PG(modules_activated) be 0.
This, in turn, precludes running RSHUTDOWN functions on modules.
2. ext/filter allocates IF_G(get_array), etc. in the course of the
request startup, and if RSHUTDOWN is not called, they are not cleaned
up.
3. Since ext/filter does not initialize IF_G arrays, on the next
request uncleaned value will be used. Since these arrays are no longer
pointing to a valid memory (which was cleaned on the end of the previous
request), this will result in a crash.
Reproduce code:
---------------
1. Create extension that uses zend_bailout in RINIT.
2. Run two requests while ext/filter is present and turned on
3. Crash!
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=47930&edit=1