Bug #75931 [Opn->Ver]: User stream filter is used after destruction

From: Date: Thu, 10 Dec 2020 14:43:15 +0000
Subject: Bug #75931 [Opn->Ver]: User stream filter is used after destruction
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230999@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75931&edit=1 ID: 75931 Updated by: cmb@php.net Reported by: ivo at beerntea dot com Summary: User stream filter is used after destruction -Status: Open +Status: Verified Type: Bug Package: Streams related Operating System: Linux x64 PHP Version: 7.2.2 Block user comment: N Private report: N New Comment: > Also note that the constructor method is never called. Documented as <http://svn.php.net/viewvc?view=revision&revision=352000>. Other than that, yes, the behavior of php://stdin is broken wrt. user filters. Previous Comments: ------------------------------------------------------------------------ [2018-02-07 16:58:25] ivo at beerntea dot com Description: ------------ A php_user_filter instance may be used by PHP's I/O functions after it (and anything it references) has been destructed. This happens when the stream the filter is bound to is closed while the process is exiting. Allowing the stream to be garbage collected before the process exits (uncomment $out = NULL; in the example below) fixes the destruction issue, but still leaves the last (closing) call to the filter method with an invalid stream resource. Manually closing the stream while it is still referenced results in correct behavior: the final filter call has a valid stream resource and destruction happens after the final call. Also note that the constructor method is never called. It might be unexpected that an object can be created without its constructor getting called. This is just a simplified test case. I was implementing a gzip stream filter (with gzip header), using the deflate_init/deflate_add methods when I ran into this problem. The deflate resource stored in a property is also cleaned up before the final filter call happens, so there is no opportunity to finalize the output. Test script: --------------- <?php class test_filter extends php_user_filter { public function __construct() { fprintf(STDERR, "filter construct\n"); } public function onCreate() { fprintf(STDERR, "filter onCreate\n"); } public function filter($in, $out, &$consumed, $closing) { fprintf(STDERR, "filter consumed=$consumed closing=".($closing ? 'true' : 'false')." stream valid=".(is_resource($this->stream) ? 'true' : 'false')."\n"); while ($bucket = stream_bucket_make_writeable($in)) { $consumed += $bucket->datalen; stream_bucket_append($out, $bucket); } return PSFS_PASS_ON; } public function onClose() { fprintf(STDERR, "filter onClose\n"); } public function __destruct() { fprintf(STDERR, "filter destruct\n"); } } stream_filter_register('test_filter', 'test_filter'); $in = fopen('php://stdin', 'r'); $out = fopen('php://stdout', 'w'); stream_filter_append($out, 'test_filter', STREAM_FILTER_WRITE, array()); stream_copy_to_stream($in, $out); //fclose($out); //$out = NULL; Expected result: ---------------- filter construct filter onCreate filter consumed=0 closing=false stream valid=true hello world filter consumed=0 closing=true stream valid=true filter onClose filter destruct Actual result: -------------- filter onCreate filter consumed=0 closing=false stream valid=true hello world filter destruct filter consumed=0 closing=true stream valid=false filter onClose ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75931&edit=1

« previous php.bugs (#230999) next »