Repository navigation
Fix use-after-free when pclose() closes a stream from its user filter - #24175
Open
EdmondDantes wants to merge 1 commit into
Open
EdmondDantes wants to merge 1 commit into
EdmondDantes wants to merge 1 commit into
Conversation
Sjord
reviewed
Oct 7, 2026
| Warning: pclose(): %d is not a valid stream resource in %s on line %d | ||
| int(-1) | ||
| int(3) | ||
| int(%i) |
Contributor
There was a problem hiding this comment.
This seems to match too much, i.e. int(-1). Perhaps check is_resource($fp) after calling pclose?
Contributor
Author
There was a problem hiding this comment.
The test looks like it was written by a paranoid person... Probably a single check would have been enough. I'll check it again.
fclose() refuses a stream marked PHP_STREAM_FLAG_NO_FCLOSE, which a user filter's callback sets on its stream; pclose() closed it anyway, freeing the stream and the filter under the running callback.
EdmondDantes
force-pushed
the
stream-pclose-in-filter
branch
from
October 7, 2026 10:12
f08b74d to
e0643a1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
While a user filter's
filter()runs, its stream carriesPHP_STREAM_FLAG_NO_FCLOSE, sofclose()from the callback fails with a warning.pclose()did not check the flag: it freed the stream and the filter under the running callback (use-after-free under Valgrind, no Fibers needed).pclose()now refuses such a stream with the same warning asfclose()and returns -1, its documented error value. One visible change:pclose()of anopendir()handle, which also carries the flag, now fails the wayfclose()of it already does.Test:
ext/standard/tests/filters/pclose_in_filter.phpt.