Bug #65593 [Asn->Csd]: Segfault when calling ob_start from output buffering callback.

From: Date: Wed, 18 Feb 2015 13:09:15 +0000
Subject: Bug #65593 [Asn->Csd]: Segfault when calling ob_start from output buffering callback.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190786@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65593&edit=1 ID: 65593 Updated by: mike@php.net Reported by: arjen at react dot com Summary: Segfault when calling ob_start from output buffering callback. -Status: Assigned +Status: Closed Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: 5.4Git-2013-08-30 (Git) Assigned To: mike Block user comment: N Private report: N New Comment: Automatic comment on behalf of mike Revision: http://git.php.net/?p=php-src.git;a=commit;h=225af964c0324b2bf14e44c0fad77198b97cc06c Log: Fixed bug #65593 (Segfault when calling ob_start from output buffering callback) Previous Comments: ------------------------------------------------------------------------ [2015-02-18 12:00:10] mike@php.net Shouldn't the engine increase the refcount of the closure while it is executing? ------------------------------------------------------------------------ [2015-02-18 11:32:27] mike@php.net Simpler test case: ob_start(function(){ob_start();}); The ob layer was not written with closures in mind. Actually I faced the exact same problem in several other extensions. @laruence, why ain't the closure just put in the GC if it cant be destroyed now? ------------------------------------------------------------------------ [2015-02-17 14:29:16] laruence@php.net we need a way to indicate dtor is called: diff --git a/main/output.c b/main/output.c index f9b8a68..34b638f 100644 --- a/main/output.c +++ b/main/output.c @@ -714,7 +714,13 @@ PHPAPI int php_output_handler_hook(php_output_handler_hook_t type, void *arg TSR * Destroy an output handler */ PHPAPI void php_output_handler_dtor(php_output_handler *handler TSRMLS_DC) { - STR_FREE(handler->name); + if (handler->name) { + STR_FREE(handler->name); + handler->name = NULL; /* prevent recursively calling to this */ + } else { + return; + } + STR_FREE(handler->buffer.data); if (handler->flags & PHP_OUTPUT_HANDLER_USER) { zval_ptr_dtor(&handler->func.user->zoh); ------------------------------------------------------------------------ [2015-02-17 14:21:54] laruence@php.net also exists in 5.5+ ------------------------------------------------------------------------ [2014-11-19 12:22:11] arjen at react dot com php has to be compiled in debug mode: php-5.6.3/bin/php ~/public_html/php/bug65593.php PHP Fatal error: Cannot destroy active lambda function in ~/public_html/php/bug65593.php on line 12 Fatal error: Cannot destroy active lambda function in ~/public_html/php/bug65593.php on line 12 [Wed Nov 19 13:15:22 2014] Script: '~/public_html/php/bug65593.php' --------------------------------------- ~/phpdebug/phpfarm/src/php-5.6.3/main/output.c(717) : Block 0x7f5a1f63ad08 status: Beginning: Cached Freed (invalid) Start: OK End: OK --------------------------------------- [Wed Nov 19 13:15:22 2014] Script: '~/public_html/php/bug65593.php' --------------------------------------- ~/phpdebug/phpfarm/src/php-5.6.3/main/output.c(718) : Block 0x7f5a1f4649c8 status: Beginning: Freed Start: OK End: Overflown (magic=0x0000005A instead of 0x2373547F) At least 4 bytes overflown --------------------------------------- Testscript can be reduced to https://gist.github.com/arjenschol/6389030#file-test-php ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=65593 -- Edit this bug report at https://bugs.php.net/bug.php?id=65593&edit=1

« previous php.bugs (#190786) next »