Bug #64776 [Opn->Csd]: The XSLT extension is not thread safe.

From: Date: Mon, 02 Dec 2013 14:01:41 +0000
Subject: Bug #64776 [Opn->Csd]: The XSLT extension is not thread safe.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183056@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64776&edit=1 ID: 64776 Updated by: mike@php.net Reported by: slangley at google dot com Summary: The XSLT extension is not thread safe. -Status: Open +Status: Closed Type: Bug Package: XSLT related Operating System: N/A PHP Version: 5.4.14 Block user comment: N Private report: N New Comment: Automatic comment on behalf of mike Revision: http://git.php.net/?p=php-src.git;a=commit;h=7cd702640de648a4fd5d49234b9ce4704c007f5d Log: Fix Bug #64776 The XSLT extension is not thread safe. Previous Comments: ------------------------------------------------------------------------ [2013-05-05 10:48:15] slangley at google dot com Description: ------------ ThreadSanitizer has detected a data race in php_xsl.c. The function xsltSetGenericErrorFunc is not thread safe, yet it can be accessed concurrently by separate threads from the request INIT & SHUTDOWN handlers in the xslt extension. /* {{{ PHP_RINIT_FUNCTION */ PHP_RINIT_FUNCTION(xsl) { xsltSetGenericErrorFunc(NULL, php_libxml_error_handler); return SUCCESS; } /* }}} */ /* {{{ PHP_RSHUTDOWN_FUNCTION */ PHP_RSHUTDOWN_FUNCTION(xsl) { xsltSetGenericErrorFunc(NULL, NULL); return SUCCESS; } xsltSetGenericErrorFunc uses two global variables to record state, with no protection against concurrent access. from xsltutils.c xmlGenericErrorFunc xsltGenericError = xsltGenericErrorDefaultFunc; void *xsltGenericErrorContext = NULL; /** * xsltSetGenericErrorFunc: * @ctx: the new error handling context * @handler: the new handler function * * Function to reset the handler and the error context for out of * context error messages. * This simply means that @handler will be called for subsequent * error messages while not parsing nor validating. And @ctx will * be passed as first argument to @handler * One can simply force messages to be emitted to another FILE * than * stderr by setting @ctx to this file handle and @handler to NULL. */ void xsltSetGenericErrorFunc(void *ctx, xmlGenericErrorFunc handler) { xsltGenericErrorContext = ctx; if (handler != NULL) xsltGenericError = handler; else xsltGenericError = xsltGenericErrorDefaultFunc; } Calling xsltSetGenericErrorFunc from the module initializer should solve this problem. Test script: --------------- build PHP with --enable-maintainer-zts. Execute concurrent requests. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=64776&edit=1

« previous php.bugs (#183056) next »