com php-src: Clear FG(user_stream_current_filename) when bailing out: NEWS ext/standard/tests/streams/ user-stream-error.phpt
main/streams/userspace.c
| From: | Sara Golemon | Date: | Wed, 12 Oct 2016 04:55:01 +0000 |
| Subject: | com php-src: Clear FG(user_stream_current_filename) when bailing out: NEWS ext/standard/tests/streams/ user-stream-error.phpt main/streams/userspace.c |
||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-94935@lists.php.net to get a copy of this message | ||
Commit: 43ccf23d700ae780451e257f5a66d4210f82f026
Author: Sara Golemon <pollita@php.net> Tue, 11 Oct 2016 21:14:25 -0700
Parents: 689a9b8def07875641b3132a82c701fb7acb676c
Branches: PHP-5.6
Link: http://git.php.net/?p=php-src.git;a=commitdiff;h=43ccf23d700ae780451e257f5a66d4210f82f026
Log:
Clear FG(user_stream_current_filename) when bailing out
If a userwrapper opener E_ERRORs then FG(user_stream_current_filename)
would remain set until the next request and would not be pointing
at unallocated memory.
Catch the bailout, clear the variable, then continue bailing.
Closes https://bugs.php.net/bug.php?id=73188
Changed paths:
M NEWS
A ext/standard/tests/streams/user-stream-error.phpt
M main/streams/userspace.c
Diff:
diff --git a/NEWS b/NEWS
index cf765ff..d9e6b4c 100644
--- a/NEWS
+++ b/NEWS
@@ -13,6 +13,7 @@ PHP NEWS
- Standard:
. Fixed bug #73203 (passing additional_parameters causes mail to fail). (cmb)
+ . Fixed bug #73188 (use after free in userspace streams). (Sara)
13 Oct 2016, PHP 5.6..27
diff --git a/ext/standard/tests/streams/user-stream-error.phpt
b/ext/standard/tests/streams/user-stream-error.phpt
new file mode 100644
index 0000000..e7351b4
--- /dev/null
+++ b/ext/standard/tests/streams/user-stream-error.phpt
@@ -0,0 +1,16 @@
+--TEST--
+E_ERROR during UserStream Open
+--FILE--
+<?php
+
+class FailStream {
+ public function stream_open($path, $mode, $options, &$opened_path) {
+ _some_undefined_function();
+ }
+}
+stream_wrapper_register('mystream', 'FailStream');
+fopen('mystream://foo', 'r');
+echo 'Done';
+
+--EXPECTF--
+Fatal error: Call to undefined function _some_undefined_function() in %s/user-stream-error.php on
line %d
diff --git a/main/streams/userspace.c b/main/streams/userspace.c
index e65f605..37c0a17 100644
--- a/main/streams/userspace.c
+++ b/main/streams/userspace.c
@@ -394,12 +394,17 @@ static php_stream *user_wrapper_opener(php_stream_wrapper *wrapper, const char
*
MAKE_STD_ZVAL(zfuncname);
ZVAL_STRING(zfuncname, USERSTREAM_OPEN, 1);
- call_result = call_user_function_ex(NULL,
- &us->object,
- zfuncname,
- &zretval,
- 4, args,
- 0, NULL TSRMLS_CC);
+ zend_try {
+ call_result = call_user_function_ex(NULL,
+ &us->object,
+ zfuncname,
+ &zretval,
+ 4, args,
+ 0, NULL TSRMLS_CC);
+ } zend_catch {
+ FG(user_stream_current_filename) = NULL;
+ zend_bailout();
+ } zend_end_try();
if (call_result == SUCCESS && zretval != NULL && zval_is_true(zretval)) {
/* the stream is now open! */