#29349 [Bgs->Opn]: imagecreatefromstring segfaults (fix included)

From: Date: Sun, 25 Jul 2004 18:54:34 +0000
Subject: #29349 [Bgs->Opn]: imagecreatefromstring segfaults (fix included)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-63503@lists.php.net to get a copy of this message
ID: 29349 User updated by: k at ailis dot de Reported By: k at ailis dot de -Status: Bogus +Status: Open Bug Type: GD related Operating System: Linux PHP Version: 4CVS-2004-07-23 (stable) New Comment: Narf... This is NOT a bug in the GD library. The function you are using is freeing memory because this function is MEANT to do exactly this because this function normally deals with data which was allocated by GD itself. But you are passing data to this function which was allocated by YOU. Boutell has already dealt with this problem and has created new functions which exactly suit your needs: The gdImageCreateFrom*Ptr functions and also the gdNewDynamicCtxEx function. RTFM: * The new gdNewDynamicCtxEx function was added to support the easy implementation of the above functions and to correct a design problem which made life unpleasant for those passing in memory not originally allocated by gd to the gdNewDynamicCtx function by providing a way to specify that gd should never free or reallocate a particular block of memory. The gdNewDynamicCtx function and its relatives, although still exported for ABI compatibility, are now deprecated except for internal use, in favor of [45]gdImageCreateFromPngPtr and its relatives. So please stop putting your head in the sand and apply Adam Conrad's patch or move to the new gdImageCreateFrom*Ptr functions. Previous Comments: ------------------------------------------------------------------------ [2004-07-25 19:28:39] iliaa@php.net Sorry, but your problem does not imply a bug in PHP itself. For a list of more appropriate places to ask for help using PHP, please visit http://www.php.net/support.php as this bug system is not the appropriate forum for asking support questions. Thank you for your interest in PHP. This is a bug in the GD library, we recommend to always use the bundled GD library, which as you've indicated does not have this problem. ------------------------------------------------------------------------ [2004-07-25 15:21:35] adconrad at debian dot org As of the next upload to the Debian archive, we will be using the following patch, which seems to clear up every php4-gd segfault bug we've had reported: --- php4-4.3.8/ext/gd/gd.c.orig 2004-07-24 06:00:25.000000000 -0600 +++ php4-4.3.8/ext/gd/gd.c 2004-07-24 06:10:38.000000000 -0600 @@ -1242,7 +1242,7 @@ #ifdef HAVE_GD_WBMP else { gdIOCtx *io_ctx; - io_ctx = gdNewDynamicCtx (8, data); + io_ctx = gdNewDynamicCtxEx (8, data, 0); if (io_ctx) { if (getmbi((int(*)(void*))gdGetC, io_ctx) == 0 && skipheader((int(*)(void*))gdGetC, io_ctx) == 0 ) { #if HAVE_LIBGD204 @@ -1274,7 +1274,7 @@ gdImagePtr im; gdIOCtx *io_ctx; - io_ctx = gdNewDynamicCtx (Z_STRLEN_PP(data), Z_STRVAL_PP(data)); + io_ctx = gdNewDynamicCtxEx (Z_STRLEN_PP(data), Z_STRVAL_PP(data), 0); if (!io_ctx) { return NULL; @@ -1428,7 +1428,7 @@ goto out_err; } - io_ctx = gdNewDynamicCtx(buff_size, buff); + io_ctx = gdNewDynamicCtxEx(buff_size, buff, 0); if(!io_ctx) { php_error_docref(NULL TSRMLS_CC, E_WARNING,"Cannot allocate GD IO context"); goto out_err; ------------------------------------------------------------------------ [2004-07-24 14:08:46] adconrad at debian dot org Also note that gdNewDynamicCtx is used 3 times in gd.c, not just once as the patch would lead one to believe. ------------------------------------------------------------------------ [2004-07-24 14:05:05] adconrad at debian dot org Note that gdNewDynamicCtxEx was added in 2.0.21, so if this is used unconditionally, PHP will need to depend on that version of libgd2. (Also, this does appear to fix the segfaults being reported all over the place for imagecreatefromstring with the external libgd2) ------------------------------------------------------------------------ [2004-07-23 14:09:13] k at ailis dot de I have searched the closed bug reports and it looks like you will find the whole problem in #24174 (including a backtrace). Your solution was to modify the bundled GD library. In my opinion this is a very bad solution because this does not fix the problem if you use the external GD library. And it seems NOT to be a bug in GD! It's seems more like a misuse of a GD-function. The external GD library AND the bundled one can be used if you try my fix and check if it does not break something else. It looks to me that Boutell has created this *CtxEx function exactly for people who want to control the memory-freeing behaviour of the function so it might be the correct solution. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/29349 -- Edit this bug report at http://bugs.php.net/?id=29349&edit=1

« previous php.bugs (#63503) next »