com php-src: Clear FG(user_stream_current_filename) when bailing out: NEWS ext/standard/tests/streams/ user-stream-error.phpt
main/streams/userspace.c

From: Date: Wed, 12 Oct 2016 04:55:01 +0000
Subject: com php-src: Clear FG(user_stream_current_filename) when bailing out: NEWS ext/standard/tests/streams/ user-stream-error.phpt
main/streams/userspace.c
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-94935@lists.php.net to get a copy of this message
Commit: 43ccf23d700ae780451e257f5a66d4210f82f026 Author: Sara Golemon <pollita@php.net> Tue, 11 Oct 2016 21:14:25 -0700 Parents: 689a9b8def07875641b3132a82c701fb7acb676c Branches: PHP-5.6 Link: http://git.php.net/?p=php-src.git;a=commitdiff;h=43ccf23d700ae780451e257f5a66d4210f82f026 Log: Clear FG(user_stream_current_filename) when bailing out If a userwrapper opener E_ERRORs then FG(user_stream_current_filename) would remain set until the next request and would not be pointing at unallocated memory. Catch the bailout, clear the variable, then continue bailing. Closes https://bugs.php.net/bug.php?id=73188 Changed paths: M NEWS A ext/standard/tests/streams/user-stream-error.phpt M main/streams/userspace.c Diff: diff --git a/NEWS b/NEWS index cf765ff..d9e6b4c 100644 --- a/NEWS +++ b/NEWS @@ -13,6 +13,7 @@ PHP NEWS - Standard: . Fixed bug #73203 (passing additional_parameters causes mail to fail). (cmb) + . Fixed bug #73188 (use after free in userspace streams). (Sara) 13 Oct 2016, PHP 5.6..27 diff --git a/ext/standard/tests/streams/user-stream-error.phpt b/ext/standard/tests/streams/user-stream-error.phpt new file mode 100644 index 0000000..e7351b4 --- /dev/null +++ b/ext/standard/tests/streams/user-stream-error.phpt @@ -0,0 +1,16 @@ +--TEST-- +E_ERROR during UserStream Open +--FILE-- +<?php + +class FailStream { + public function stream_open($path, $mode, $options, &$opened_path) { + _some_undefined_function(); + } +} +stream_wrapper_register('mystream', 'FailStream'); +fopen('mystream://foo', 'r'); +echo 'Done'; + +--EXPECTF-- +Fatal error: Call to undefined function _some_undefined_function() in %s/user-stream-error.php on line %d diff --git a/main/streams/userspace.c b/main/streams/userspace.c index e65f605..37c0a17 100644 --- a/main/streams/userspace.c +++ b/main/streams/userspace.c @@ -394,12 +394,17 @@ static php_stream *user_wrapper_opener(php_stream_wrapper *wrapper, const char * MAKE_STD_ZVAL(zfuncname); ZVAL_STRING(zfuncname, USERSTREAM_OPEN, 1); - call_result = call_user_function_ex(NULL, - &us->object, - zfuncname, - &zretval, - 4, args, - 0, NULL TSRMLS_CC); + zend_try { + call_result = call_user_function_ex(NULL, + &us->object, + zfuncname, + &zretval, + 4, args, + 0, NULL TSRMLS_CC); + } zend_catch { + FG(user_stream_current_filename) = NULL; + zend_bailout(); + } zend_end_try(); if (call_result == SUCCESS && zretval != NULL && zval_is_true(zretval)) { /* the stream is now open! */

« previous php.cvs (#94935) next »