#19243 [Fbk->Opn]: Seg Fault Restoring Session Variables with References to Objects

From: Date: Thu, 05 Sep 2002 21:41:25 +0000
Subject: #19243 [Fbk->Opn]: Seg Fault Restoring Session Variables with References to Objects
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-18540@lists.php.net to get a copy of this message
ID: 19243 User updated by: fdruseikis@sc.rr.com Reported By: fdruseikis@sc.rr.com -Status: Feedback +Status: Open Bug Type: Session related Operating System: Linux RH 7.0 PHP Version: 4.2.2 New Comment: I'll give it a try. Previous Comments: ------------------------------------------------------------------------ [2002-09-05 15:48:06] sniper@php.net Please try using this CVS snapshot: http://snaps.php.net/php4-latest.tar.gz For Windows: http://snaps.php.net/win32/php4-win32-latest.zip ------------------------------------------------------------------------ [2002-09-05 15:04:16] kalowsky@php.net Can you try one of the new snapshots please? There has been some work on the way sessions are delt with, and while I don't think it fixes this problem... hey it's worth a shot. Regardless, I don't think what you're doing is really going to ever work. I agree with yohgaki that we should throw some warnings or something. ------------------------------------------------------------------------ [2002-09-05 08:05:00] fdruseikis@sc.rr.com BTW this is not a problem if the references are not global, for example, interior variables in an array instead. For example, $x = array(9,8,7); $o1 = array(1,2,3,null,null); $o1[2] =& $x; $o1[3] =& $x; This array clearly has references within it and shares the array named by $x. Conclusion: It would seem to have something to do with restoring a reference to something that is already global. IMO the serialization formats clearly intend to support serializing/deserializing of references. The system provided deserializer needs to restore references correctly by implementing the inverse of the process that the serializer performed, which appearantly is not working correctly. All the information you need is in the session file. It also means that the closure of all references implict in an object (or array) need to be captured, which is clearly being done in the array example above. Not to put too fine a point on it: "This kind of thing is done in Java all the time." If your recommendation is taken, then you need to clarify the restriction in the documentation on references and in the session functions. You're talking about a rat's nest of exceptions here. Sometimes works for arrays, don't work for globals, etc. It would be easier to make it work. Give me a hint - where is the de/serializer implemented? ------------------------------------------------------------------------ [2002-09-05 06:19:05] yohgaki@php.net Don't do that. It will never work. We should raise error and ignore references. ------------------------------------------------------------------------ [2002-09-05 05:03:07] fdruseikis@sc.rr.com The following script demonstrates a problem with restoring session variables that have references to objects. Variables o1 and o2 are supposed to be globals refering to the same object instance. First GET request initializes; POST request changes state. Crash occurs on first POST or second GET. Apache 1.3.26 reports a segmentation fault. Browser (lynx) indicates "Unexpected Network Read Error; ..." If you remove 'o2' from session_register() and initialize the reference to o1 in the POST the crash goes away. Fred Druseikis -------------------- <snip> ----------------------------- <?php # vim: ts=4 filetype=php # segmentation fault on restore of object references class TFoo { var $c; function TFoo($c) { $this->c = $c; } function inc() { $this->c++; } } global $o1, $o2; session_register('o1', 'o2' ); session_start(); if( $_SERVER['REQUEST_METHOD'] == 'GET' ) { echo "GET<br>"; $o1 =& new TFoo(42); $o2 =& $o1; } if( $_SERVER['REQUEST_METHOD'] == 'POST' ) { echo "POST<br>"; } $o1->inc(); $o2->inc(); echo "<tt>o1</tt><br><pre>"; print_r($o1); echo "</pre>"; echo "<tt>o2</tt><br><pre>"; print_r($o2); echo "</pre>"; ?> <html> <head> </head> <body> <form action='/web/a/register/foo.php' method='post' > <input type='text' name='x' value='42' /> <input type='submit' name='submit' value='Submit' /> </form> </body> </html> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=19243&edit=1

« previous php.bugs (#18540) next »