Skip to content

Commit 2d17f00

Browse files
committed
ext/standard: Fix stream use after error handler in stream_get_meta_data
Fixes GH-23262
1 parent 802f920 commit 2d17f00

2 files changed

Lines changed: 47 additions & 1 deletion

File tree

‎ext/standard/streamsfuncs.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -563,7 +563,6 @@ PHP_FUNCTION(stream_get_meta_data)
563563
add_assoc_bool(return_value, "blocked", 1);
564564
add_assoc_bool(return_value, "eof", php_stream_eof(stream));
565565
}
566-
php_stream_error_operation_end_for_stream(stream);
567566

568567
if (!Z_ISUNDEF(stream->wrapperdata)) {
569568
Z_ADDREF_P(&stream->wrapperdata);
@@ -598,6 +597,7 @@ PHP_FUNCTION(stream_get_meta_data)
598597
add_assoc_string(return_value, "uri", stream->orig_path);
599598
}
600599

600+
php_stream_error_operation_end_for_stream(stream);
601601
}
602602
/* }}} */
603603

Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
--TEST--
2+
GH-23262 (stream_get_meta_data() uses the stream after error_handler closes it)
3+
--FILE--
4+
<?php
5+
class InvalidEofStream
6+
{
7+
public $context;
8+
9+
public function stream_open($path, $mode, $options, &$openedPath): bool
10+
{
11+
return true;
12+
}
13+
14+
public function stream_eof()
15+
{
16+
return [];
17+
}
18+
19+
public function stream_stat(): array
20+
{
21+
return [];
22+
}
23+
}
24+
25+
stream_wrapper_register('invalid-eof', InvalidEofStream::class);
26+
27+
$stream = null;
28+
$context = stream_context_create([
29+
'stream' => [
30+
'error_mode' => StreamErrorMode::Silent,
31+
'error_handler' => static function (array $errors) use (&$stream): void {
32+
echo "handler: {$errors[0]->code->name}\n";
33+
fclose($stream);
34+
},
35+
],
36+
]);
37+
38+
$stream = fopen('invalid-eof://input', 'r', false, $context);
39+
$meta = stream_get_meta_data($stream);
40+
var_dump($meta['eof'], $meta['wrapper_type'], $meta['uri']);
41+
?>
42+
--EXPECT--
43+
handler: UserspaceInvalidReturn
44+
bool(true)
45+
string(10) "user-space"
46+
string(19) "invalid-eof://input"

0 commit comments

Comments
 (0)