Repository navigation
Conversation
LamentXU123
approved these changes
Oct 4, 2026
LamentXU123
left a comment
Member
There was a problem hiding this comment.
I think the idea is good. I'd prefer you add the following tests though
--TEST--
ZipArchive mutators throw when called from a cancel callback during close()
--EXTENSIONS--
zip
--SKIPIF--
<?php
if (!method_exists(ZipArchive::class, 'registerCancelCallback')) {
die('skip cancel callbacks are not supported');
}
?>
--FILE--
<?php
$filename = __DIR__ . '/zip_close_mutator_reentry_cancel.zip';
$zip = new ZipArchive();
$zip->open($filename, ZipArchive::CREATE | ZipArchive::OVERWRITE);
$zip->addFromString('a.txt', str_repeat('a', 100000));
$zip->addFromString('b.txt', str_repeat('b', 100000));
$zip->registerCancelCallback(function () use ($zip) {
static $done = false;
if ($done) {
return 0;
}
$done = true;
$mutators = [
'deleteIndex' => fn() => $zip->deleteIndex(0),
'addFromString' => fn() => $zip->addFromString('c.txt', 'c'),
'registerCancelCallback' => fn() => $zip->registerCancelCallback(fn() => 0),
];
foreach ($mutators as $name => $mutator) {
try {
var_dump($mutator());
} catch (Error $e) {
echo $name, ': ', $e::class, ': ', $e->getMessage(), PHP_EOL;
}
}
return 0;
});
var_dump($zip->close());
var_dump($zip->open($filename, ZipArchive::CHECKCONS));
var_dump($zip->numFiles);
var_dump($zip->getFromName('a.txt') === str_repeat('a', 100000));
var_dump($zip->getFromName('b.txt') === str_repeat('b', 100000));
$zip->close();
?>
--CLEAN--
<?php
@unlink(__DIR__ . '/zip_close_mutator_reentry_cancel.zip');
?>
--EXPECT--
deleteIndex: Error: Already being closed
addFromString: Error: Already being closed
registerCancelCallback: Error: Already being closed
bool(true)
bool(true)
int(2)
bool(true)
bool(true)
and
--TEST--
ZipArchive mutators throw when open() implicitly closes the previous archive
--EXTENSIONS--
zip
--SKIPIF--
<?php
if (!method_exists(ZipArchive::class, 'registerProgressCallback')) {
die('skip progress callbacks are not supported');
}
?>
--FILE--
<?php
$filename = __DIR__ . '/zip_close_mutator_reentry_open.zip';
$nextFilename = __DIR__ . '/zip_close_mutator_reentry_open_next.zip';
$zip = new ZipArchive();
$zip->open($filename, ZipArchive::CREATE | ZipArchive::OVERWRITE);
$zip->addFromString('a.txt', str_repeat('a', 100000));
$zip->addFromString('b.txt', str_repeat('b', 100000));
$zip->registerProgressCallback(0.0, function ($rate) use ($zip) {
static $done = false;
if ($done || $rate <= 0) {
return;
}
$done = true;
$mutators = [
'deleteIndex' => fn() => $zip->deleteIndex(0),
'addFromString' => fn() => $zip->addFromString('c.txt', 'c'),
'registerProgressCallback' => fn() => $zip->registerProgressCallback(0.5, function () {}),
];
foreach ($mutators as $name => $mutator) {
try {
var_dump($mutator());
} catch (Error $e) {
echo $name, ': ', $e::class, ': ', $e->getMessage(), PHP_EOL;
}
}
});
var_dump($zip->open($nextFilename, ZipArchive::CREATE | ZipArchive::OVERWRITE));
var_dump($zip->addFromString('new.txt', 'new contents'));
var_dump($zip->close());
var_dump($zip->open($filename, ZipArchive::CHECKCONS));
var_dump($zip->numFiles);
var_dump($zip->getFromName('a.txt') === str_repeat('a', 100000));
var_dump($zip->getFromName('b.txt') === str_repeat('b', 100000));
$zip->close();
var_dump($zip->open($nextFilename, ZipArchive::CHECKCONS));
var_dump($zip->numFiles);
var_dump($zip->getFromName('new.txt') === 'new contents');
$zip->close();
?>
--CLEAN--
<?php
@unlink(__DIR__ . '/zip_close_mutator_reentry_open.zip');
@unlink(__DIR__ . '/zip_close_mutator_reentry_open_next.zip');
?>
--EXPECT--
deleteIndex: Error: Already being closed
addFromString: Error: Already being closed
registerProgressCallback: Error: Already being closed
bool(true)
bool(true)
bool(true)
bool(true)
int(2)
bool(true)
bool(true)
bool(true)
int(1)
bool(true)
A progress or cancel callback runs inside zip_close() after libzip has fixed the list of entries it writes. Deleting or unchanging an entry from the callback frees a dirent that zip_close() still uses, and other changes are either dropped or make the close fail and lose the archive. Throw the Error that close() and open() already raise in that state from every method that modifies the archive.
iliaal
force-pushed
the
fix/aph-zip-close-mutator-reentry-v0oc-84-work
branch
from
October 4, 2026 14:29
831fe15 to
dd200bb
Compare
Member
Author
|
Thanks, added both |
LamentXU123
approved these changes
Oct 8, 2026
LamentXU123
left a comment
Member
There was a problem hiding this comment.
LGTM. Please leave this to me I want to check this again before I merge.
LamentXU123
added a commit
that referenced
this pull request
Oct 8, 2026
* PHP-8.6: ext/zip: Reject ZipArchive mutators during close() (#24025)
Member
|
Thanks! |
damek24
pushed a commit
to damek24/php-src
that referenced
this pull request
Oct 8, 2026
* PHP-8.4: ext/zip: Reject ZipArchive mutators during close() (php#24025)
damek24
pushed a commit
to damek24/php-src
that referenced
this pull request
Oct 8, 2026
* PHP-8.5: ext/zip: Reject ZipArchive mutators during close() (php#24025)
arnaud-lb
added a commit
to frodeborli/php-src
that referenced
this pull request
Oct 9, 2026
* up/master: (180 commits) Changed the test expected result of `pdo_mysql/bug76815_pdo_mysql_f to %d (php#13808) ext/standard: name the real parameter in the unpack() offset error (php#24215) ext/readline: Refactor CLI readline completion generators Fix phpGH-24081: User opcode DISPATCH runs on a stale frame in the TAILCALL VM ext/standard: Validate the bcrypt cost before reading it JIT: Avoid object type check if the object is known to be a type (php#24086) zend_alloc: move a small block shrunk to the size of the bin below Fix phpGH-23979: Nullsafe operator must not flush delayed oplines of an enclosing function ext/zip: Reject ZipArchive mutators during close() (php#24025) Fix OSS-Fuzz #568005340: FETCH_DIM_FUNC_ARG partial conversion Fix too wide type inference for ASSIGN_DIM_OP Fix type inference of ADD_ARRAY_UNPACK with integer keys Evaluate ZEND_SPACESHIP in SCCP Add range inference for SPACESHIP JIT: Optimize array checks in comparisons (php#24084) Fix leak when the added previous exception is already in the chain (php#24177) date: Add `php_date_time_duration_create()` in a new `time_duration.h` (php#24072) ext/zip: Fix use-after-free in the archive destructor path (php#23779) ext/standard: Optimize array_chunk() by filling packed chunks directly Fix phpGH-17626: JIT corrupts opline handler when blacklisting root trace ...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to GH-23749. A progress or cancel callback runs inside zip_close() after libzip has built the list of entries it will write, so changing the archive from the callback is never honored and can crash: deleteIndex(0) from a progress callback segfaults on a freed or NULLed dirent, deleting a later entry makes close() fail with "Internal error" and lose the archive, and additions are silently dropped. Every method that modifies the archive now throws the same "Already being closed" Error that close() and open() raise since GH-23749, through the php_zipobj_closing() helper that already exists on 8.6. Read-only methods are unchanged since libzip already refuses to reopen an entry it is writing. The zip_close() in the destructor does not set the flag; #23779 handles that separately.
/cc @devnexen