Bug #64893 [Opn]: Crash due to dtor call happening after dtor shutdown

From: Date: Tue, 31 Dec 2013 15:00:09 +0000
Subject: Bug #64893 [Opn]: Crash due to dtor call happening after dtor shutdown
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183513@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64893&edit=1

 ID:                 64893
 Updated by:         nikic@php.net
 Reported by:        nikic@php.net
 Summary:            Crash due to dtor call happening after dtor shutdown
 Status:             Open
 Type:               Bug
 Package:            Scripting Engine problem
 PHP Version:        5.5.0RC1
-Assigned To:        
+Assigned To:        dmitry
 Block user comment: N
 Private report:     N

 New Comment:

Dmitry, do you think we could swap steps 2 and 3 of the php_request_shutdown process, i.e. flush OB
first and then call dtors? (See http://lxr.php.net/xref/PHP_TRUNK/main/main.c#1747)

I think step 3 is the last one where user code (that potentially creates objects) can be run, so it
would make sense to run the dtors after that. Or does that cause other issues?


Previous Comments:
------------------------------------------------------------------------
[2013-10-04 08:17:18] arjen at react dot com

The result '/home/nikic/dev/php-dev/Zend/zend_hash.c(946) : ht=0x42dea5c is already
destroyed' only happens in a debug build.

In a normal build, a notice about a undefined variable $GLOBALS is generated: 
http://3v4l.org/jcBu6

------------------------------------------------------------------------
[2013-05-21 22:42:59] nikic@php.net

Description:
------------
If an object is created *after* the destructor shutdown, its dtor will be called when it is freed,
which potentially happens during a phase of the shutdown process where the executor is no longer in
a consistent state.

The test script uses the ob callback (called after dtor shutdown) to create an object and bind it to
to the error callback, which is later freed during zend_deactivate, as part of the executor
shutdown.

Result:
/home/nikic/dev/php-dev/Zend/zend_hash.c(946) : ht=0x42dea5c is already destroyed

Test script:
---------------
<?php
 
ob_start(function() {
    $foo = new Foo;
    set_error_handler(function() use ($foo) {});
});

class Foo {
    public function __destruct() {
        var_dump($GLOBALS);
    }
}




------------------------------------------------------------------------



-- 
Edit this bug report at https://bugs.php.net/bug.php?id=64893&edit=1


Thread (5 messages)

« previous php.bugs (#183513) next »