PHP 4.0 Bug #3291: SAPI_POST_READER_FUNC(...) & erealloc(...) work incorrect

From: Date: Mon, 24 Jan 2000 10:37:50 +0000
Subject: PHP 4.0 Bug #3291: SAPI_POST_READER_FUNC(...) & erealloc(...) work incorrect
Groups: php.dev 
Request: Send a blank email to php-dev+get-14863@lists.php.net to get a copy of this message
From: anton@concord.ru Operating system: WinNT 4.0+SP 4+IIS 4.0 PHP version: 4.0 Beta 3 PHP Bug Type: Scripting Engine problem Bug description: SAPI_POST_READER_FUNC(...) & erealloc(...) work incorrect Part two of report bug number #3041: "I can confirm identical behaviour on my NT box with the cgi version of 4.0b3, however the ISAPI version hangs even with very small graphic files (eg 1K). After the hang, the php isapi module cannot be used without stopping and starting iis." I localized this bug. SAPI_POST_READER_FUNC(sapi_read_standard_form_data) function from SAPI.c call erealloc(...) function in cycle to increase buffer size for readed post data and return pointer to new empty portion. On first step of cycle all ok, on second step all ok, but on third step of cycle pointer to buffer (pointer returned by erealloc(...) function) for readed data was changed on size greater then total_read_bytes+SAPI_POST_BLOCK_SIZE+1 and sapi_module.read_post(SG(request_info).post_data+total_read_bytes, SAPI_POST_BLOCK_SIZE SLS_CC) hangs. Anton Kalmykov. anton@concord.ru

« previous php.dev (#14863) next »