#19243 [Ana->Fbk]: Seg Fault Restoring Session Variables with References to Objects
| From: | kalowsky@php.net | Date: | Thu, 05 Sep 2002 20:04:16 +0000 |
| Subject: | #19243 [Ana->Fbk]: Seg Fault Restoring Session Variables with References to Objects | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-18512@lists.php.net to get a copy of this message | ||
ID: 19243
Updated by: kalowsky@php.net
Reported By: fdruseikis@sc.rr.com
-Status: Analyzed
+Status: Feedback
Bug Type: Reproducible crash
Operating System: Linux RH 7.0
PHP Version: 4.2.2
New Comment:
Can you try one of the new snapshots please? There has been some work
on the way sessions are delt with, and while I don't think it fixes
this problem... hey it's worth a shot. Regardless, I don't think what
you're doing is really going to ever work. I agree with yohgaki that
we should throw some warnings or something.
Previous Comments:
------------------------------------------------------------------------
[2002-09-05 08:05:00] fdruseikis@sc.rr.com
BTW this is not a problem if the references are not global, for
example, interior variables in an array instead. For example,
$x = array(9,8,7);
$o1 = array(1,2,3,null,null);
$o1[2] =& $x;
$o1[3] =& $x;
This array clearly has references within it and shares the array named
by $x.
Conclusion: It would seem to have something to do with restoring a
reference to something that is already global.
IMO the serialization formats clearly intend to support
serializing/deserializing of references. The system provided
deserializer needs to restore references correctly by implementing the
inverse of the process that the serializer performed, which appearantly
is not working correctly. All the information you need is in the
session file. It also means that the closure of all references implict
in an object (or array) need to be captured, which is clearly being
done in the array example above.
Not to put too fine a point on it: "This kind of thing is done in Java
all the time."
If your recommendation is taken, then you need to clarify the
restriction in the documentation on references and in the session
functions. You're talking about a rat's nest of exceptions here.
Sometimes works for arrays, don't work for globals, etc.
It would be easier to make it work.
Give me a hint - where is the de/serializer implemented?
------------------------------------------------------------------------
[2002-09-05 06:19:05] yohgaki@php.net
Don't do that. It will never work.
We should raise error and ignore references.
------------------------------------------------------------------------
[2002-09-05 05:03:07] fdruseikis@sc.rr.com
The following script demonstrates a problem with restoring session
variables that have references to objects.
Variables o1 and o2 are supposed to be globals refering to the same
object instance. First GET request initializes; POST request changes
state. Crash occurs on first POST or second GET.
Apache 1.3.26 reports a segmentation fault. Browser (lynx) indicates
"Unexpected Network Read Error; ..."
If you remove 'o2' from session_register() and initialize the reference
to o1 in the POST the crash goes away.
Fred Druseikis
-------------------- <snip> -----------------------------
<?php
# vim: ts=4 filetype=php
# segmentation fault on restore of object references
class TFoo {
var $c;
function TFoo($c) {
$this->c = $c;
}
function inc() {
$this->c++;
}
}
global $o1, $o2;
session_register('o1', 'o2' );
session_start();
if( $_SERVER['REQUEST_METHOD'] == 'GET' ) {
echo "GET<br>";
$o1 =& new TFoo(42);
$o2 =& $o1;
}
if( $_SERVER['REQUEST_METHOD'] == 'POST' ) {
echo "POST<br>";
}
$o1->inc();
$o2->inc();
echo "<tt>o1</tt><br><pre>"; print_r($o1); echo
"</pre>";
echo "<tt>o2</tt><br><pre>"; print_r($o2); echo
"</pre>";
?>
<html>
<head>
</head>
<body>
<form action='/web/a/register/foo.php' method='post' >
<input type='text' name='x' value='42' />
<input type='submit' name='submit' value='Submit' />
</form>
</body>
</html>
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=19243&edit=1