Skip to content

Commit f2d96c8

Browse files
committed
Merge branch 'PHP-8.5'
* PHP-8.5: ext/session: Fix memory leak due to multiple exception happening during session abort
2 parents 873468c + 10e02b0 commit f2d96c8

File tree

3 files changed

+47
-1
lines changed

3 files changed

+47
-1
lines changed

ext/session/session.c

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,7 @@
4141
#include "ext/standard/url_scanner_ex.h"
4242
#include "ext/standard/info.h"
4343
#include "zend_smart_str.h"
44+
#include "zend_exceptions.h"
4445
#include "ext/standard/url.h"
4546
#include "ext/standard/basic_functions.h"
4647
#include "ext/standard/head.h"
@@ -1724,8 +1725,16 @@ PHPAPI php_session_status php_get_session_status(void)
17241725
static bool php_session_abort(void)
17251726
{
17261727
if (PS(session_status) == php_session_active) {
1727-
if (PS(mod_data) || PS(mod_user_implemented)) {
1728+
if ((PS(mod_data) || PS(mod_user_implemented)) && PS(mod)->s_close) {
1729+
zend_object *old_exception = EG(exception);
1730+
EG(exception) = NULL;
1731+
17281732
PS(mod)->s_close(&PS(mod_data));
1733+
if (!EG(exception)) {
1734+
EG(exception) = old_exception;
1735+
} else if (old_exception) {
1736+
zend_exception_set_previous(EG(exception), old_exception);
1737+
}
17291738
}
17301739
PS(session_status) = php_session_none;
17311740
return true;
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
--TEST--
2+
SessionHandler::validateId must return bool
3+
--INI--
4+
session.use_strict_mode=1
5+
--EXTENSIONS--
6+
session
7+
--SKIPIF--
8+
<?php include('skipif.inc'); ?>
9+
--FILE--
10+
<?php
11+
class MySession extends SessionHandler {
12+
public function validateId($key) {
13+
return null;
14+
}
15+
}
16+
17+
$handler = new MySession();
18+
19+
try {
20+
session_set_save_handler($handler);
21+
session_start();
22+
} catch (TypeError $e) {
23+
echo $e->getMessage(), "\n";
24+
}
25+
26+
session_write_close();
27+
28+
try {
29+
session_start();
30+
} catch (Throwable $e) {
31+
echo $e->getMessage(), "\n";
32+
}
33+
?>
34+
--EXPECTF--
35+
Session id must be a string

ext/session/tests/user_session_module/session_set_save_handler_class_012.phpt

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,8 @@ var_dump(session_id(), $oldHandler, ini_get('session.save_handler'), $handler->i
4343
--EXPECTF--
4444
*** Testing session_set_save_handler() : incorrect arguments for existing handler open ***
4545
Open:
46+
47+
Warning: SessionHandler::close(): Parent session handler is not open in %s on line %d
4648
SessionHandler::open() expects exactly 2 arguments, 0 given
4749

4850
Warning: Undefined global variable $_SESSION in %s on line %d

0 commit comments

Comments
 (0)