[php-src] Issue #7875: mail() logging might be unsafe in combination with an error handler converting errors into exceptions
| From: | TimWolla | Date: | Mon, 03 Jan 2022 15:02:33 +0000 |
| Subject: | [php-src] Issue #7875: mail() logging might be unsafe in combination with an error handler converting errors into exceptions | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-238733@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/7875
Comment Author: TimWolla
It is correct that this issue would not happen with the error handler converting the warning into an
Exception. However an error handler like that certainly is nothing out of the usual. In fact such an
error handler [is an example within the official PHP
manual](https://www.php.net/manual/en/class.errorexception.php#errorexception.example.error-handler)
(that's the source of the error handler in my example script). Large Frameworks such as Laravel
also use an error handler similar to our error handler: https://github.com/laravel/framework/blob/fada7461eca5e2719b81894219da52b11724dd6d/src/Illuminate/Foundation/Bootstrap/HandleExceptions.php#L68-L76.
In many cases it is helpful to treat PHP warnings and notices as exceptions, because they indicate
some programming error more often than not.
However this issue would not happen if this error handler would actually throw the exception and
thus abort execution at the place where the warning is emitted, instead of proceeding with the
execution of the native function and only then throwing the exception. This is a behavior that
differs from userland functions [1] and certainly is unexpected. There's also no easy way to
work around this issue, except switching out the error handler before calling
mail().
[1] I understand why that might be: The error handler itself might call mail() while
one call to mail() already is in progress.