Bug #80602 [Ver->Csd]: Segfault when using DOMChildNode::before()

From: Date: Thu, 30 Mar 2023 19:02:20 +0000
Subject: Bug #80602 [Ver->Csd]: Segfault when using DOMChildNode::before()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-244066@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80602&edit=1

 ID:                 80602
 Updated by:         git@php.net
 Reported by:        jules dot bernable at gmail dot com
 Summary:            Segfault when using DOMChildNode::before()
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            DOM XML related
 Operating System:   debian
 PHP Version:        8.0.0
 Assigned To:        beberlei
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of NathanFreeman (author) and nielsdos (committer)
Revision: https://github.com/php/php-src/commit/2d6decc14c977159b90e9dcfa0c562c01794c12a
Log: Fix bug #80602: Segfault when using DOMChildNode::before()


Previous Comments:
------------------------------------------------------------------------
[2023-01-25 03:27:15] kertzmann8 at gmail dot com

I’ve especially stayed aware of the article and I will get many benefits from it.

------------------------------------------------------------------------
[2022-06-14 17:06:35] cmb@php.net

The following pull request has been associated:

Patch Name: Fix bug #80602
On GitHub:  https://github.com/php/php-src/pull/8729
Patch:      https://github.com/php/php-src/pull/8729.patch

------------------------------------------------------------------------
[2021-02-01 22:25:59] beberlei@php.net

Confusingly, it segfaults with $target->before('bar',
$doc->documentElement->firstChild, 'baz');

but it works with $target->before($doc->documentElement->firstChild, 'baz'); or
even $target->before($doc->documentElement->firstChild);

------------------------------------------------------------------------
[2021-01-18 16:14:04] beberlei@php.net

Confirmed, will take a look asap.

------------------------------------------------------------------------
[2021-01-18 16:05:28] nikic@php.net

I believe this happens because https://github.com/php/php-src/blob/d340be0d3246542c1ae34d632f36510fb1792852/ext/dom/parentnode.c#L184
can free "newNode" according to libxml docs:

> Add a new node to @parent, at the end of the child (or property) list merging adjacent TEXT
> nodes (in which case @cur is freed)

This seems like rather peculiar behavior, guess that it's necessary to handle text nodes in
some other way that does not end up destroying them?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80602


--
Edit this bug report at https://bugs.php.net/bug.php?id=80602&edit=1


Thread (8 messages)

« previous php.bugs (#244066) next »