Bug #81294 [Ver->Csd]: Segfault when removing a filter

From: Date: Tue, 27 Jul 2021 10:17:27 +0000
Subject: Bug #81294 [Ver->Csd]: Segfault when removing a filter
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235393@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81294&edit=1 ID: 81294 Updated by: git@php.net Reported by: ivo dot andonov at gmail dot com Summary: Segfault when removing a filter -Status: Verified +Status: Closed Type: Bug Package: Streams related Operating System: Linux / Windows PHP Version: 7.4 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb69 Revision: https://github.com/php/php-src/commit/1fa26eccbaec3dc6ce645db144f08f46b63c1d59 Log: Fix #81294: Segfault when removing a filter Previous Comments: ------------------------------------------------------------------------ [2021-07-26 12:13:24] cmb@php.net The following pull request has been associated: Patch Name: Fix #81294: Segfault when removing a filter On GitHub: https://github.com/php/php-src/pull/7308 Patch: https://github.com/php/php-src/pull/7308.patch ------------------------------------------------------------------------ [2021-07-26 11:59:26] cmb@php.net Changing to "Streams related", since "Filter related" is often misused for ext/filter. ------------------------------------------------------------------------ [2021-07-25 20:21:19] requinix@php.net https://github.com/php/php-src/blob/PHP-8.0.8/main/streams/filter.c#L419 Given that the definition of fops->filter is php_stream_filter_status_t (*filter)( php_stream *stream, php_stream_filter *thisfilter, php_stream_bucket_brigade *buckets_in, php_stream_bucket_brigade *buckets_out, size_t *bytes_consumed, int flags ); it does seem odd to call with "thisfilter" as something different. ------------------------------------------------------------------------ [2021-07-25 19:13:37] ivo dot andonov at gmail dot com Description: ------------ This one seems to be sourced back since quite some time (at least from 5.6.30 till 8.0.8). Right now I do not have the time for posting too many details but it should be pretty clear to understand by looking at streams/filter.c, function _php_stream_filter_flush, then the loop with current = filter and then referencing filter->fops->filter() instead of current->fops->filter(). Test script: --------------- class some_user_filter { ... } stream_filter_register("some.filter", "some_user_filter"); $f = fopen("test", "wb"); $flt1 = stream_filter_append($f, "zlib.deflate", STREAM_FILTER_WRITE); $flt2 = stream_filter_append($f, "some.filter", STREAM_FILTER_WRITE); fwrite($f, "test"); stream_filter_remove($flt1); // this line will fail and at the end of the script a segfault / or MS Don't send / access violation fwrite($f, "test"1); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81294&edit=1

« previous php.bugs (#235393) next »