Bug #74408 [Com]: Endless loop bypassing execution time limit

From: Date: Thu, 11 May 2017 15:18:52 +0000
Subject: Bug #74408 [Com]: Endless loop bypassing execution time limit
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209060@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74408&edit=1 ID: 74408 Comment by: info at ihead dot ru Reported by: andy_2639 at justmail dot de Summary: Endless loop bypassing execution time limit Status: Closed Type: Bug Package: Scripting Engine problem Operating System: Windows 10 Pro x64 PHP Version: 7.1.3 Block user comment: N Private report: N New Comment: It would better to allow change type of timer, used by max_execution_time: ITIMER_PROF or ITIMER_REAL. ITIMER_PROF used on Unix now. Previous Comments: ------------------------------------------------------------------------ [2017-04-11 10:47:13] laruence@php.net Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=eb03f16442c7ee10842dde0140b933d2be60b84b Log: Fixed bug #74408 (Endless loop bypassing execution time limit) ------------------------------------------------------------------------ [2017-04-10 17:46:30] andy_2639 at justmail dot de Description: ------------ The test script hangs with eating one core completely. Even after the execution time limit is exceeded, php does not abort. I had to kill php-cgi.exe via task manager. This might allow DoS attacks to shared hosters where an attacker can upload its own code. I guess that there is a ping-pong between the error_handler and the exception_handler (deprecation warning of static call to non-static method and instanciating an object of unknown class). Test script: --------------- <?php // php.ini: error_reporting = E_ALL | E_DEPRECATED | E_STRICT class ErrorHandling { public function error_handler(int $errno, string $errstr, string $errfile, int $errline): void { $bla = new NonExistingClass2(); } public function exception_handler(Throwable $e): void { } } set_error_handler('ErrorHandling::error_handler'); set_exception_handler('ErrorHandling::exception_handler'); $blubb = new NonExistingClass(); Expected result: ---------------- Best case: printing an error message and stopping the script. At least I expect the script to be aborted after the execution time limit exceeds. Actual result: -------------- PHP runs eating a core fully without increasing its memory need until I kill php-cgi.exe via task manager. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74408&edit=1

« previous php.bugs (#209060) next »