Bug #81294 [Ver]: Segfault when removing a filter

From: Date: Mon, 26 Jul 2021 11:59:26 +0000
Subject: Bug #81294 [Ver]: Segfault when removing a filter
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235356@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81294&edit=1

 ID:                 81294
 Updated by:         cmb@php.net
 Reported by:        ivo dot andonov at gmail dot com
 Summary:            Segfault when removing a filter
 Status:             Verified
 Type:               Bug
-Package:            Filter related
+Package:            Streams related
 Operating System:   Linux / Windows
 PHP Version:        7.4
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Changing to "Streams related", since "Filter related" is often
misused for ext/filter.


Previous Comments:
------------------------------------------------------------------------
[2021-07-25 20:21:19] requinix@php.net

https://github.com/php/php-src/blob/PHP-8.0.8/main/streams/filter.c#L419

Given that the definition of fops->filter is

php_stream_filter_status_t (*filter)(
  php_stream *stream,
  php_stream_filter *thisfilter,
  php_stream_bucket_brigade *buckets_in,
  php_stream_bucket_brigade *buckets_out,
  size_t *bytes_consumed,
  int flags
 );

it does seem odd to call with "thisfilter" as something different.

------------------------------------------------------------------------
[2021-07-25 19:13:37] ivo dot andonov at gmail dot com

Description:
------------
This one seems to be sourced back since quite some time (at least from 5.6.30 till 8.0.8). Right now
I do not have the time for posting too many details but it should be pretty clear to understand by
looking at streams/filter.c, function _php_stream_filter_flush, then the loop with current = filter
and then referencing filter->fops->filter() instead of current->fops->filter().



Test script:
---------------
class some_user_filter {
...
}
stream_filter_register("some.filter", "some_user_filter");
$f = fopen("test", "wb");
$flt1 = stream_filter_append($f, "zlib.deflate", STREAM_FILTER_WRITE);
$flt2 = stream_filter_append($f, "some.filter", STREAM_FILTER_WRITE);
fwrite($f, "test");
stream_filter_remove($flt1); // this line will fail and at the end of the script a segfault / or MS
Don't send / access violation
fwrite($f, "test"1);




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81294&edit=1


Thread (5 messages)

« previous php.bugs (#235356) next »