Why module shutdown function is not called for openssl extension?
| From: | Kamesh Jayachandran | Date: | Mon, 25 Oct 2004 15:40:37 +0000 |
| Subject: | Why module shutdown function is not called for openssl extension? | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-13505@lists.php.net to get a copy of this message | ||
Hi All,
I have identified a defect in openssl extension code. Even though it is
not critical and not likely to happen. Let me explain the scenario.
<?php
$dn = array(
"countryName" => "TestCountry",
"stateOrProvinceName" => "TestSrate",
"localityName" => "TestLocality",
"organizationName" => "Test Organisation",
"organizationalUnitName" => "Test organisational Unit",
"commonName" => "Test common name",
"emailAddress" => "mymail@mail.com"
);
$privkey = openssl_pkey_new();
$csr = openssl_csr_new($dn, $privkey);
?>
The above scenario causes a segfault in NetWare but not on Linux. I did
not try on windows.
openssl_csr_new will fail because maxlength of countryName is 2
characters.
During the failure openssl_csr_new is not setting req.priv_key to NULL
this causes dispose function to free the req.priv_key.
As a part of php_request_shutdown $privkey is again freed(second time).
This causes a seg fault in NetWare.
Can I go ahead and set req.priv_key = NULL when php_openssl_make_REQ
returns failure and we_made_the_key == 0?
I have seen shutdown function is set to NULL even though it is defined.
With regards
Kamesh Jayachandran