Re: Forbid rebinding scope of closures created by ReflectionFunctionAbstract::getClosure()

From: Date: Sat, 10 Oct 2015 18:51:40 +0000
Subject: Re: Forbid rebinding scope of closures created by ReflectionFunctionAbstract::getClosure()
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-88739@lists.php.net to get a copy of this message
Hi Nikita, Nikita Popov wrote:
We have recently been reviewing the interaction between ReflectionFunctionAbstract::getClosure(), a mechanism which converts an ordinary function or method into a "fake" closure, and closure rebinding using Closure::bindTo() and Closure::call(). It turns out that this combination has not yet received testing and multiple crashes and leaks were found and fixed [1] [2] [3] [4].
In hindsight, it is probably my fault that this wasn't spotted sooner. I should've considered the case of ::getClosure() when I wrote Closure::call().
We have one last outstanding changeset [5] waiting to land, which we want to check back with internals first, as it constitutes a BC break late in the PHP 7.0 release cycle. This changeset forbids rebinding the *scope* of closures returned by getClosure() completely.
This sounds like a reasonable approach to dealing with the problem. We already have some restrictions with internal function Closures anyway, I don't think this will hurt much, especially since cases where you need to rebind methods into different scopes are quite rare. So, +1 from me. Thanks. -- Andrea Faulds http://ajf.me/

« previous php.internals (#88739) next »