Bug #65593 [Asn]: Segfault when calling ob_start from output buffering callback.
| From: | mike@php.net | Date: | Wed, 18 Feb 2015 12:00:11 +0000 |
| Subject: | Bug #65593 [Asn]: Segfault when calling ob_start from output buffering callback. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190784@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65593&edit=1
ID: 65593
Updated by: mike@php.net
Reported by: arjen at react dot com
Summary: Segfault when calling ob_start from output buffering
callback.
Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: 5.4Git-2013-08-30 (Git)
Assigned To: mike
Block user comment: N
Private report: N
New Comment:
Shouldn't the engine increase the refcount of the closure while it is executing?
Previous Comments:
------------------------------------------------------------------------
[2015-02-18 11:32:27] mike@php.net
Simpler test case:
ob_start(function(){ob_start();});
The ob layer was not written with closures in mind.
Actually I faced the exact same problem in several other extensions.
@laruence, why ain't the closure just put in the GC if it cant be destroyed now?
------------------------------------------------------------------------
[2015-02-17 14:29:16] laruence@php.net
we need a way to indicate dtor is called:
diff --git a/main/output.c b/main/output.c
index f9b8a68..34b638f 100644
--- a/main/output.c
+++ b/main/output.c
@@ -714,7 +714,13 @@ PHPAPI int php_output_handler_hook(php_output_handler_hook_t type, void *arg
TSR
* Destroy an output handler */
PHPAPI void php_output_handler_dtor(php_output_handler *handler TSRMLS_DC)
{
- STR_FREE(handler->name);
+ if (handler->name) {
+ STR_FREE(handler->name);
+ handler->name = NULL; /* prevent recursively calling to this */
+ } else {
+ return;
+ }
+
STR_FREE(handler->buffer.data);
if (handler->flags & PHP_OUTPUT_HANDLER_USER) {
zval_ptr_dtor(&handler->func.user->zoh);
------------------------------------------------------------------------
[2015-02-17 14:21:54] laruence@php.net
also exists in 5.5+
------------------------------------------------------------------------
[2014-11-19 12:22:11] arjen at react dot com
php has to be compiled in debug mode:
php-5.6.3/bin/php ~/public_html/php/bug65593.php
PHP Fatal error: Cannot destroy active lambda function in ~/public_html/php/bug65593.php on line 12
Fatal error: Cannot destroy active lambda function in ~/public_html/php/bug65593.php on line 12
[Wed Nov 19 13:15:22 2014] Script: '~/public_html/php/bug65593.php'
---------------------------------------
~/phpdebug/phpfarm/src/php-5.6.3/main/output.c(717) : Block 0x7f5a1f63ad08 status:
Beginning: Cached
Freed (invalid)
Start: OK
End: OK
---------------------------------------
[Wed Nov 19 13:15:22 2014] Script: '~/public_html/php/bug65593.php'
---------------------------------------
~/phpdebug/phpfarm/src/php-5.6.3/main/output.c(718) : Block 0x7f5a1f4649c8 status:
Beginning: Freed
Start: OK
End: Overflown (magic=0x0000005A instead of 0x2373547F)
At least 4 bytes overflown
---------------------------------------
Testscript can be reduced to https://gist.github.com/arjenschol/6389030#file-test-php
------------------------------------------------------------------------
[2014-11-19 09:13:50] mike@php.net
Doesn't seem to be an issue anymore?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=65593
--
Edit this bug report at https://bugs.php.net/bug.php?id=65593&edit=1