Bug #70970 [PATCH]: Segfault when combining error handler with output buffering
| From: | laruence@php.net | Date: | Wed, 25 Nov 2015 16:09:15 +0000 |
| Subject: | Bug #70970 [PATCH]: Segfault when combining error handler with output buffering | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197419@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70970&edit=1
ID: 70970
Patch added by: laruence@php.net
Reported by: sebastian@php.net
Summary: Segfault when combining error handler with output
buffering
Status: Closed
Type: Bug
Package: Output Control
Operating System: Linux
PHP Version: 7.0Git-2015-11-25 (Git)
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
The following patch has been added/updated:
Patch Name: bug70970.patch
Revision: 1448467753
URL: https://bugs.php.net/patch-display.php?bug=70970&patch=bug70970.patch&revision=1448467753
Previous Comments:
------------------------------------------------------------------------
[2015-11-25 16:08:55] laruence@php.net
instead of the patch I attached, I prefer to make this thing simple and safe, that is restore the
catchable error to fatal error.
we may fix this in master but not sure whether it's worthy to do so.
------------------------------------------------------------------------
[2015-11-25 16:01:00] laruence@php.net
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=4a7e83f54aeb6d5464da6cc2b201ce47a23a88d9
Log: Fixed bug #70970 (Segfault when combining error handler with output buffering)
------------------------------------------------------------------------
[2015-11-25 13:30:04] sebastian@php.net
Description:
------------
While researching the changes made to output buffering in PHP 7 for a book I am working on with Arne
Blankerts and Stefan Priebsch, Arne discovered the segfault shown below.
Of course, the code shown does not make any sense. Yet it should not lead to a segfault in PHP.
Test script:
---------------
<?php
function exception_error_handler($severity, $message, $file, $line)
{
throw new ErrorException($message, 0, $severity, $file, $line);
}
set_error_handler('exception_error_handler');
function obHandler($buffer, $phase = null)
{
try {
ob_start();
} catch (\Throwable $e) {
return (string) $e;
}
return $buffer;
}
ob_start('obHandler');
print 'test';
Actual result:
--------------
#0 0x0000000000985e06 in zend_fcall_info_args_clear (fci=0x7372656c, free_mem=1) at
/usr/local/src/php/src/Zend/zend_API.c:3427
#1 0x0000000000986368 in zend_fcall_info_argv (fci=0x7372656c, argc=0, argv=0x7fffffffbcc0) at
/usr/local/src/php/src/Zend/zend_API.c:3534
#2 0x000000000098653d in zend_fcall_info_argn (fci=0x7372656c, argc=0) at
/usr/local/src/php/src/Zend/zend_API.c:3556
#3 0x0000000000903731 in php_output_handler_op (handler=0x7fffee46a2a0, context=0x7fffffffbe30)
at /usr/local/src/php/src/main/output.c:977
#4 0x0000000000903ef7 in php_output_stack_pop (flags=1) at
/usr/local/src/php/src/main/output.c:1221
#5 0x0000000000901fd9 in php_output_end_all () at /usr/local/src/php/src/main/output.c:341
#6 0x00000000008e9682 in php_request_shutdown (dummy=0x0) at
/usr/local/src/php/src/main/main.c:1777
#7 0x0000000000a37286 in do_cli (argc=2, argv=0x1357390) at
/usr/local/src/php/src/sapi/cli/php_cli.c:1142
#8 0x0000000000a3796e in main (argc=2, argv=0x1357390) at
/usr/local/src/php/src/sapi/cli/php_cli.c:1345
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70970&edit=1