Bug #77693 [Fbk->Opn]: Crash on multiple separate exception thrown inside custom error handler

From: Date: Tue, 05 Mar 2019 14:27:50 +0000
Subject: Bug #77693 [Fbk->Opn]: Crash on multiple separate exception thrown inside custom error handler
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219849@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77693&edit=1

 ID:                 77693
 Updated by:         nikic@php.net
 Reported by:        jean dot beguin at free dot fr
 Summary:            Crash on multiple separate exception thrown inside
                     custom error handler
-Status:             Feedback
+Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Windows 7 & Ubuntu 18.04
 PHP Version:        7.3.2
 Block user comment: N
 Private report:     N

 New Comment:

This is a stack overflow caused by a destruction of a deeply nested object. This happens because the
exception captures backtrace arguments and the error handler is passed the variable scope of the
error, which also includes the previous exception in $e. This creates a chain of exceptions.

In PHP 8 the error context is gone, not sure if there's anything actionable here before that.
The fact that exceptions capture backtrace args is a common problem for a number of reasons, we
might want to address that in some way (possibly ini option to disable).


Previous Comments:
------------------------------------------------------------------------
[2019-03-05 13:31:08] danack@php.net

Generating the backtrace on Ubuntu would probably be best.

As you're seeing this crash under both OSes, if you can also run a memory checker on your
machine...

------------------------------------------------------------------------
[2019-03-05 13:29:30] danack@php.net

Thank you for this bug report. To properly diagnose the problem, we
need a backtrace to see what is happening behind the scenes. To
find out how to generate a backtrace, please read
http://bugs.php.net/bugs-generating-backtrace.php
for *NIX and
http://bugs.php.net/bugs-generating-backtrace-win32.php
for Win32

Once you have generated a backtrace, please submit it to this bug
report and change the status back to "Open". Thank you for helping
us make PHP better.



------------------------------------------------------------------------
[2019-03-05 12:50:29] jean dot beguin at free dot fr

Description:
------------
When running the test script, the apache server processes crashes with exit status 3221225725.

The timing is of no importance as this still crash after around the same number of cycles, even with
a sleep inside the loop.

This crash persists even with the use of gc_collect_cycles().

Tested on:
  Windows 7, Apache 2.4.38, PHP 7.3.2 via XAMPP
  Windows 7, Apache 2.4.29, PHP 7.2.2 via XAMPP
  Ubuntu Server 18.04, Apache/2.4.29 (Ubuntu), PHP 7.2.15-0ubuntu0.18.04.1


Test script:
---------------
<?php 

error_reporting(E_ALL);

function errorHandler(int $errorNumber, string $errorMessage)
{
    throw new \Exception();
}

$previousHandler = set_error_handler("errorHandler");

// 1000 is enough to crash on Windows 7 with XAMPP, but more is needed for Ubuntu
$operations = 10000;

for($i = 0; $i < $operations; $i++) {
    try{
        //Used to generate a warning.
        $inexistant[0];
    } catch (\Exception $e) {}
}

set_error_handler($previousHandler);

Expected result:
----------------
The process should not crash, as exception are thrown, caught and discarded, and should be garbage
collected.

Actual result:
--------------
Apache error.loh:
[mpm_winnt:notice] [pid 6000:tid 244] AH00428: Parent: child process 3904 exited with status
3221225725 -- Restarting.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77693&edit=1


Thread (5 messages)

« previous php.bugs (#219849) next »