PHP 4.0 Bug #3626: php_mcal.c segmentation fault

From: Date: Fri, 25 Feb 2000 22:21:37 +0000
Subject: PHP 4.0 Bug #3626: php_mcal.c segmentation fault
Groups: php.dev 
Request: Send a blank email to php-dev+get-16017@lists.php.net to get a copy of this message
From: ron@srx.com Operating system: linux PHP version: 4.0 Beta 4 Patch Level 1 PHP Bug Type: Reproduceable crash Bug description: php_mcal.c segmentation fault Description: See http://sourceforge.net/bugs/?func=detailbug&bug_id=100445&group_id=482 followup. php crashes using mcal - seems to me that this is due to the use of automatic variables for pval start, end and recurend in make_event_object in php_mcal.c. The calls to add_assoc_object add these automatics to the return value, but the data is trashed on return from the function call. Changing these to <pval *> and calling MAKE_STD_ZVAL on them (along with fixing all the &xxx to xxx) fixes this problem. I am not an expert on php so I don't know if any 'free' calls are necessary or if this will cause a memory leak. Short script for reproducing problem: $ cat bugreport.php <html> <head> <title>Ron's Calendar</title> <LINK REL="stylesheet" HREF="calstyle.css" TYPE="text/css"> </head> <body> <center> <script language="php"> $montharray=array( "", "January", "February", "March", "April", "May", "June", "July", "August", "September", "October", "November", "December"); $current_date=getdate(); if(empty($month)) { $month=$current_date[mon]; } if(empty($year)) { $year=$current_date[year]; } # echo "checking for highlight ... $year==$current_date[year]/$month==$current_date[mon]"; if ( ($year == $current_date[year]) && ( $month == $current_date[mon]) ) { $thisday = $current_date[mday]; # echo "will highlight day $thisday<br>"; } $stream=mcal_open( "{/mstore}", "xxxxx", "xxxxxxx"); if ($stream == false) { echo "<b>Failed to open calendar!</b><br>"; } $days=mcal_days_in_month($month,mcal_is_leap_year($year)); $startday=mcal_day_of_week($year,$month,1); #echo "<p>Getting events between $year/$month/1 and $year/$month/$days from stream $stream ...</p>"; $events=mcal_list_events($stream, $year, $month, 1, $year, $month, $days); #echo "<p>Found " . count($events) . " events ...</p>"; for($x=0;$x<count($events);$x++) { # echo "<p>Fetching event $events[$x]"; $event=mcal_fetch_event($stream,$events[$x]); # echo "<p>Found event $event title $event->title, public $event->public, category $event->category description $event->description"; $ev_mday=$event->start->mday; $date_array[$ev_mday]="view"; # echo "<p>Updating mday $ev_mday: " . $date_array[$ev_mday]; } #echo "<br>"; $backmonth_month = $month == 1 ? 12 : $month - 1 ; $backmonth_year = $month == 1 ? $year - 1 : $year; $frwdmonth_month = $month == 12 ? 1 : $month + 1; $frwdmonth_year = $month == 12 ? $year + 1 : $year; </script> </body> </html> Output from script: $ php ../bugreport.php X-Powered-By: PHP/4.0b4pl1 Content-Type: text/html <html> <head> <title>Ron's Calendar</title> <LINK REL="stylesheet" HREF="calstyle.css" TYPE="text/css"> </head> <body> <center> Segmentation fault Possible solution: Here's a diff/patch for beta 4 pl1 that stops the segmentation fault and allows the use of mcal calendars (I can supply a text file if requested - send email): *** php_mcal.c.orig Fri Feb 25 16:44:33 2000 --- php_mcal.c Fri Feb 25 16:44:33 2000 *************** *** 221,227 **** } ! static int add_assoc_object(pval *arg, char *key, pval tmp) { #ifdef ZEND_VERSION HashTable *symtable; --- 221,227 ---- } ! static int add_assoc_object(pval *arg, char *key, pval * tmp) { #ifdef ZEND_VERSION HashTable *symtable; *************** *** 462,501 **** void make_event_object(pval *mypvalue,CALEVENT *event) { ! pval start,end,recurend; object_init(mypvalue); add_property_long(mypvalue,"id",event->id); add_property_long(mypvalue,"public",event->public); ! object_init(&start); if(event->start.has_date) { ! add_property_long(&start,"year",event->start.year); ! add_property_long(&start,"month",event->start.mon); ! add_property_long(&start,"mday",event->start.mday); } if(event->start.has_time) { ! add_property_long(&start,"hour",event->start.hour); ! add_property_long(&start,"min",event->start.min); ! add_property_long(&start,"sec",event->start.sec); } add_assoc_object(mypvalue, "start",start); ! object_init(&end); if(event->end.has_date) { ! add_property_long(&end,"year",event->end.year); ! add_property_long(&end,"month",event->end.mon); ! add_property_long(&end,"mday",event->end.mday); } if(event->end.has_time) { ! add_property_long(&end,"hour",event->end.hour); ! add_property_long(&end,"min",event->end.min); ! add_property_long(&end,"sec",event->end.sec); } add_assoc_object(mypvalue, "end",end); --- 462,503 ---- void make_event_object(pval *mypvalue,CALEVENT *event) { ! pval *start,*end,*recurend; object_init(mypvalue); add_property_long(mypvalue,"id",event->id); add_property_long(mypvalue,"public",event->public); ! MAKE_STD_ZVAL(start); ! object_init(start); if(event->start.has_date) { ! add_property_long(start,"year",event->start.year); ! add_property_long(start,"month",event->start.mon); ! add_property_long(start,"mday",event->start.mday); } if(event->start.has_time) { ! add_property_long(start,"hour",event->start.hour); ! add_property_long(start,"min",event->start.min); ! add_property_long(start,"sec",event->start.sec); } add_assoc_object(mypvalue, "start",start); ! MAKE_STD_ZVAL(end); ! object_init(end); if(event->end.has_date) { ! add_property_long(end,"year",event->end.year); ! add_property_long(end,"month",event->end.mon); ! add_property_long(end,"mday",event->end.mday); } if(event->end.has_time) { ! add_property_long(end,"hour",event->end.hour); ! add_property_long(end,"min",event->end.min); ! add_property_long(end,"sec",event->end.sec); } add_assoc_object(mypvalue, "end",end); *************** *** 509,526 **** add_property_long(mypvalue,"alarm",event->alarm); add_property_long(mypvalue,"recur_type",event->recur_type); add_property_long(mypvalue,"recur_interval",event->recur_interval); ! object_init(&recurend); if(event->recur_enddate.has_date) { ! add_property_long(&recurend,"year",event->recur_enddate.year); ! add_property_long(&recurend,"month",event->recur_enddate.mon); ! add_property_long(&recurend,"mday",event->recur_enddate.mday); } if(event->recur_enddate.has_time) { ! add_property_long(&recurend,"hour",event->recur_enddate.hour); ! add_property_long(&recurend,"min",event->recur_enddate.min); ! add_property_long(&recurend,"sec",event->recur_enddate.sec); } add_assoc_object(mypvalue, "recur_enddate",recurend); add_property_long(mypvalue,"recur_data",event->recur_data.weekly_wday); --- 511,529 ---- add_property_long(mypvalue,"alarm",event->alarm); add_property_long(mypvalue,"recur_type",event->recur_type); add_property_long(mypvalue,"recur_interval",event->recur_interval); ! MAKE_STD_ZVAL(recurend); ! object_init(recurend); if(event->recur_enddate.has_date) { ! add_property_long(recurend,"year",event->recur_enddate.year); ! add_property_long(recurend,"month",event->recur_enddate.mon); ! add_property_long(recurend,"mday",event->recur_enddate.mday); } if(event->recur_enddate.has_time) { ! add_property_long(recurend,"hour",event->recur_enddate.hour); ! add_property_long(recurend,"min",event->recur_enddate.min); ! add_property_long(recurend,"sec",event->recur_enddate.sec); } add_assoc_object(mypvalue, "recur_enddate",recurend); add_property_long(mypvalue,"recur_data",event->recur_data.weekly_wday); Output after patch: $ php ../bugreport.php X-Powered-By: PHP/4.0b4pl1 Content-Type: text/html <html> <head> <title>Ron's Calendar</title> <LINK REL="stylesheet" HREF="calstyle.css" TYPE="text/css"> </head> <body> <center> </body> </html>

« previous php.dev (#16017) next »