[php-src] Issue #13044: exception and error handlers not called from within ob_start callback

From: Date: Thu, 28 Dec 2023 21:50:51 +0000
Subject: [php-src] Issue #13044: exception and error handlers not called from within ob_start callback
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-246152@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/13044 Author: kkmuffme ### Description The following code: ```php <?php function log_it($type, $message) { file_put_contents('/a.log', $message); } function log_it_exception($e) { file_put_contents('/a.log', $e->getMessage()); } set_error_handler('log_it'); set_exception_handler('log_it_exception'); function foo($arg) { some_func($arg); // same with exceptions //throw new Exception('message'); return $arg; } ob_start('foo'); echo 'this is your API key'; ``` Resulted in this output: ``` ``` But I expected this output instead: ``` a.log should have been created ``` It seems the error/exception handlers are not called if the error occurs inside a ob_start callback function, the default PHP error handler is called instead. I couldn't find this to be documented anywhere and this is something that should get fixed, as this can cause leaking of PII or secrets into the standard error log, which is normally prevented when using custom error handlers. ### PHP Version 8.3 (error exists in previous versions too) ### Operating System _No response_

« previous php.bugs (#246152) next »