1
0
mirror of https://github.com/php/php-src.git synced 2026-03-24 00:02:20 +01:00
Files
archived-php-src/win32/globals.c
Niels Dossche fb3536fd60 Fix leak+crash with sapi_windows_set_ctrl_handler()
The ctrl_handler is never destroyed. We have to destroy it at request
end so we avoid leaking it and also avoid keeping a reference to
previous request memory in a next request. The latter can result in a
crash and can be demonstrated with this script and `--repeat 2`:

```php
class Test {
	public function set() {
		sapi_windows_set_ctrl_handler(self::cb(...));
	}
	public function cb() {
	}
}

$test = new Test;
$test->set();
sleep(3);
```
When you hit CTRL+C in the second request you can crash.

This patch resolves both the leak and crash by destroying the
ctrl_handler after a request.

Closes GH-18231.
2025-05-05 19:13:39 +02:00

70 lines
2.1 KiB
C

/*
+----------------------------------------------------------------------+
| Copyright (c) The PHP Group |
+----------------------------------------------------------------------+
| This source file is subject to version 3.01 of the PHP license, |
| that is bundled with this package in the file LICENSE, and is |
| available through the world-wide-web at the following url: |
| https://www.php.net/license/3_01.txt |
| If you did not receive a copy of the PHP license and are unable to |
| obtain it through the world-wide-web, please send a note to |
| license@php.net so we can mail you a copy immediately. |
+----------------------------------------------------------------------+
| Author: Wez Furlong <wez@php.net> |
+----------------------------------------------------------------------+
*/
#include "php.h"
#include "php_win32_globals.h"
#include "syslog.h"
#ifdef ZTS
PHPAPI int php_win32_core_globals_id;
#else
php_win32_core_globals the_php_win32_core_globals;
#endif
void php_win32_core_globals_ctor(void *vg)
{/*{{{*/
php_win32_core_globals *wg = (php_win32_core_globals*)vg;
memset(wg, 0, sizeof(*wg));
wg->mail_socket = INVALID_SOCKET;
wg->log_source = INVALID_HANDLE_VALUE;
}/*}}}*/
void php_win32_core_globals_dtor(void *vg)
{/*{{{*/
php_win32_core_globals *wg = (php_win32_core_globals*)vg;
if (wg->registry_key) {
RegCloseKey(wg->registry_key);
wg->registry_key = NULL;
}
if (wg->registry_event) {
CloseHandle(wg->registry_event);
wg->registry_event = NULL;
}
if (wg->registry_directories) {
zend_hash_destroy(wg->registry_directories);
free(wg->registry_directories);
wg->registry_directories = NULL;
}
if (INVALID_SOCKET != wg->mail_socket) {
closesocket(wg->mail_socket);
wg->mail_socket = INVALID_SOCKET;
}
}/*}}}*/
PHP_RSHUTDOWN_FUNCTION(win32_core_globals)
{/*{{{*/
closelog();
php_win32_signal_ctrl_handler_request_shutdown();
return SUCCESS;
}/*}}}*/