ID: 11826
Updated by: alindeman
Reported By: aral@aralbalkan.com
Old Status: Feedback
Status: Closed
Bug Type: Reproducible crash
Operating System: WinMe, Linux
PHP Version: 4.0.4
New Comment:
no feedback
Previous Comments:
------------------------------------------------------------------------
[2001-07-09 16:38:59] manuel@php.net
Sascha's patch does not fix the problem, which is inconsistent memory
allocation handling by strtok function, but suppresses the sympthom which
is the crash.
Now, it just leaks memory which is good enough for normal use, but I
suppose that somebody with time and patience ought to double-check all
memory allocations that are stored in global variables like strtok_string
when made from session handler functions.
------------------------------------------------------------------------
[2001-07-09 14:30:03] sniper@php.net
Please try the latest CVS from http://snaps.php.net/
or for Windows: http://www.zend.com/snapshots/
--Jani
------------------------------------------------------------------------
[2001-07-09 11:24:37] rasmus@php.net
Your test handler doesn't crash PHP for me with the latest CVS version on Linux.
------------------------------------------------------------------------
[2001-07-08 18:32:29] manuel@php.net
I have isolated the bug but did not find the cause. It makes strtok()
crash when attempting to free memory that has been trashed.
It only happens when strtok is called from session on read or on write
handles. I could not find what is wrong in strtok but I suspect there is
inconsistent use of PHP internal global variables (strtok_string) inside
session handle functions. So it seems to be a serious PHP bug that may
also crash scripts that use strtok or other functions from inside session
handle functions that use PHP internal global variables
Metabase is no longer affected by this PHP bug because I have banned all
the uses of strtok function. A new version of Metabase was uploaded to
http://phpclasses.UpperDesign.com/browse.html/package/20
. If you use
Metabase for session handling your are strongly encouraged to download this
version.
For reproducing the PHP strtok bug without Metabase, try the script below.
<?php
function on_session_start ($save_path, $session_name)
{
return true;
}
function on_session_end()
{
return true;
}
function on_session_read ($key)
{
return true;
}
function on_session_write ($key, $val)
{
$query="SELECT * FROM sessions";
$select=(strtolower(strtok($query," "))=="select");
return true;
}
function on_session_destroy ($key)
{
return true;
}
function on_session_gc ($max_lifetime)
{
return true;
}
// Set the save handlers
session_set_save_handler("on_session_start", "on_session_end",
"on_session_read", "on_session_write",
"on_session_destroy", "on_session_gc");
session_start();
// Register the $counter variable as part of the sesssion
session_register('counter');
$counter = 1;
echo 'Session test started';
?>
------------------------------------------------------------------------
[2001-07-07 19:59:23] joey@php.net
Most likely, none of the developers are actually USING
Metabase, so this bug is simply getting glossed over.
Perhaps a reproducible test case that does not require
usage or knowledge of Metabase would help...
IE, while we really appreciate all the work you have
gone through to document this bug, and make these scripts
available, until we can see the bug OUTSIDE of the Metabase
package, it probably won't get a lot of attention.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/?id=11826
Edit this bug report at http://bugs.php.net/?id=11826&edit=1