Bug #70970 [PATCH]: Segfault when combining error handler with output buffering

From: Date: Wed, 25 Nov 2015 16:09:15 +0000
Subject: Bug #70970 [PATCH]: Segfault when combining error handler with output buffering
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197419@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70970&edit=1 ID: 70970 Patch added by: laruence@php.net Reported by: sebastian@php.net Summary: Segfault when combining error handler with output buffering Status: Closed Type: Bug Package: Output Control Operating System: Linux PHP Version: 7.0Git-2015-11-25 (Git) Assigned To: laruence Block user comment: N Private report: N New Comment: The following patch has been added/updated: Patch Name: bug70970.patch Revision: 1448467753 URL: https://bugs.php.net/patch-display.php?bug=70970&patch=bug70970.patch&revision=1448467753 Previous Comments: ------------------------------------------------------------------------ [2015-11-25 16:08:55] laruence@php.net instead of the patch I attached, I prefer to make this thing simple and safe, that is restore the catchable error to fatal error. we may fix this in master but not sure whether it's worthy to do so. ------------------------------------------------------------------------ [2015-11-25 16:01:00] laruence@php.net Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=4a7e83f54aeb6d5464da6cc2b201ce47a23a88d9 Log: Fixed bug #70970 (Segfault when combining error handler with output buffering) ------------------------------------------------------------------------ [2015-11-25 13:30:04] sebastian@php.net Description: ------------ While researching the changes made to output buffering in PHP 7 for a book I am working on with Arne Blankerts and Stefan Priebsch, Arne discovered the segfault shown below. Of course, the code shown does not make any sense. Yet it should not lead to a segfault in PHP. Test script: --------------- <?php function exception_error_handler($severity, $message, $file, $line) { throw new ErrorException($message, 0, $severity, $file, $line); } set_error_handler('exception_error_handler'); function obHandler($buffer, $phase = null) { try { ob_start(); } catch (\Throwable $e) { return (string) $e; } return $buffer; } ob_start('obHandler'); print 'test'; Actual result: -------------- #0 0x0000000000985e06 in zend_fcall_info_args_clear (fci=0x7372656c, free_mem=1) at /usr/local/src/php/src/Zend/zend_API.c:3427 #1 0x0000000000986368 in zend_fcall_info_argv (fci=0x7372656c, argc=0, argv=0x7fffffffbcc0) at /usr/local/src/php/src/Zend/zend_API.c:3534 #2 0x000000000098653d in zend_fcall_info_argn (fci=0x7372656c, argc=0) at /usr/local/src/php/src/Zend/zend_API.c:3556 #3 0x0000000000903731 in php_output_handler_op (handler=0x7fffee46a2a0, context=0x7fffffffbe30) at /usr/local/src/php/src/main/output.c:977 #4 0x0000000000903ef7 in php_output_stack_pop (flags=1) at /usr/local/src/php/src/main/output.c:1221 #5 0x0000000000901fd9 in php_output_end_all () at /usr/local/src/php/src/main/output.c:341 #6 0x00000000008e9682 in php_request_shutdown (dummy=0x0) at /usr/local/src/php/src/main/main.c:1777 #7 0x0000000000a37286 in do_cli (argc=2, argv=0x1357390) at /usr/local/src/php/src/sapi/cli/php_cli.c:1142 #8 0x0000000000a3796e in main (argc=2, argv=0x1357390) at /usr/local/src/php/src/sapi/cli/php_cli.c:1345 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70970&edit=1

« previous php.bugs (#197419) next »