Skip to content

Zend: Skip frameless registration for temporary modules - #421

Closed
iliaal wants to merge 2 commits into
PHP-8.4from
fix/aph-flf-dl-stale-handler
Closed

iliaal wants to merge 2 commits into
PHP-8.4from
fix/aph-flf-dl-stale-handler

Conversation

@iliaal

@iliaal iliaal commented Sep 29, 2026

Copy link
Copy Markdown
Owner

dl() registers a module as MODULE_TEMPORARY, but zend_register_functions still stored its frameless handlers in the process-global tables. Request shutdown frees those function records, and a later request that maps the extension at the same address dispatches through the freed record. Temporary modules now leave the frameless info unset, so the call uses the ordinary internal path. Persistent modules still receive frameless info.

dl() modules are MODULE_TEMPORARY. Their function records are freed at
request shutdown, but zend_flf_functions keeps those pointers for the
process lifetime. A later request can match the stale handler address
and use the freed record. Temporary modules leave the frameless info
unset, so the call uses the ordinary internal path.
The 32-bit CI job exited 1 with no child output. Probe setarch -R
and skip when that personality cannot be set.
@iliaal

iliaal commented Sep 30, 2026

Copy link
Copy Markdown
Owner Author

Promoted to php#24008.

@iliaal iliaal closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant