Skip to content

ext/zip: Reject ZipArchive mutators during close() - #24025

Closed
iliaal wants to merge 1 commit into
php:PHP-8.4from
iliaal:fix/aph-zip-close-mutator-reentry-v0oc-84-work
Closed

iliaal wants to merge 1 commit into
php:PHP-8.4from
iliaal:fix/aph-zip-close-mutator-reentry-v0oc-84-work

Conversation

@iliaal

@iliaal iliaal commented Sep 30, 2026

Copy link
Copy Markdown
Member

Follow-up to GH-23749. A progress or cancel callback runs inside zip_close() after libzip has built the list of entries it will write, so changing the archive from the callback is never honored and can crash: deleteIndex(0) from a progress callback segfaults on a freed or NULLed dirent, deleting a later entry makes close() fail with "Internal error" and lose the archive, and additions are silently dropped. Every method that modifies the archive now throws the same "Already being closed" Error that close() and open() raise since GH-23749, through the php_zipobj_closing() helper that already exists on 8.6. Read-only methods are unchanged since libzip already refuses to reopen an entry it is writing. The zip_close() in the destructor does not set the flag; #23779 handles that separately.

/cc @devnexen

@LamentXU123 LamentXU123 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the idea is good. I'd prefer you add the following tests though

--TEST--
ZipArchive mutators throw when called from a cancel callback during close()
--EXTENSIONS--
zip
--SKIPIF--
<?php
if (!method_exists(ZipArchive::class, 'registerCancelCallback')) {
    die('skip cancel callbacks are not supported');
}
?>
--FILE--
<?php
$filename = __DIR__ . '/zip_close_mutator_reentry_cancel.zip';
$zip = new ZipArchive();
$zip->open($filename, ZipArchive::CREATE | ZipArchive::OVERWRITE);
$zip->addFromString('a.txt', str_repeat('a', 100000));
$zip->addFromString('b.txt', str_repeat('b', 100000));
$zip->registerCancelCallback(function () use ($zip) {
    static $done = false;
    if ($done) {
        return 0;
    }
    $done = true;
    $mutators = [
        'deleteIndex' => fn() => $zip->deleteIndex(0),
        'addFromString' => fn() => $zip->addFromString('c.txt', 'c'),
        'registerCancelCallback' => fn() => $zip->registerCancelCallback(fn() => 0),
    ];
    foreach ($mutators as $name => $mutator) {
        try {
            var_dump($mutator());
        } catch (Error $e) {
            echo $name, ': ', $e::class, ': ', $e->getMessage(), PHP_EOL;
        }
    }
    return 0;
});
var_dump($zip->close());
var_dump($zip->open($filename, ZipArchive::CHECKCONS));
var_dump($zip->numFiles);
var_dump($zip->getFromName('a.txt') === str_repeat('a', 100000));
var_dump($zip->getFromName('b.txt') === str_repeat('b', 100000));
$zip->close();
?>
--CLEAN--
<?php
@unlink(__DIR__ . '/zip_close_mutator_reentry_cancel.zip');
?>
--EXPECT--
deleteIndex: Error: Already being closed
addFromString: Error: Already being closed
registerCancelCallback: Error: Already being closed
bool(true)
bool(true)
int(2)
bool(true)
bool(true)

and

--TEST--
ZipArchive mutators throw when open() implicitly closes the previous archive
--EXTENSIONS--
zip
--SKIPIF--
<?php
if (!method_exists(ZipArchive::class, 'registerProgressCallback')) {
    die('skip progress callbacks are not supported');
}
?>
--FILE--
<?php
$filename = __DIR__ . '/zip_close_mutator_reentry_open.zip';
$nextFilename = __DIR__ . '/zip_close_mutator_reentry_open_next.zip';
$zip = new ZipArchive();
$zip->open($filename, ZipArchive::CREATE | ZipArchive::OVERWRITE);
$zip->addFromString('a.txt', str_repeat('a', 100000));
$zip->addFromString('b.txt', str_repeat('b', 100000));
$zip->registerProgressCallback(0.0, function ($rate) use ($zip) {
    static $done = false;
    if ($done || $rate <= 0) {
        return;
    }
    $done = true;
    $mutators = [
        'deleteIndex' => fn() => $zip->deleteIndex(0),
        'addFromString' => fn() => $zip->addFromString('c.txt', 'c'),
        'registerProgressCallback' => fn() => $zip->registerProgressCallback(0.5, function () {}),
    ];
    foreach ($mutators as $name => $mutator) {
        try {
            var_dump($mutator());
        } catch (Error $e) {
            echo $name, ': ', $e::class, ': ', $e->getMessage(), PHP_EOL;
        }
    }
});
var_dump($zip->open($nextFilename, ZipArchive::CREATE | ZipArchive::OVERWRITE));
var_dump($zip->addFromString('new.txt', 'new contents'));
var_dump($zip->close());
var_dump($zip->open($filename, ZipArchive::CHECKCONS));
var_dump($zip->numFiles);
var_dump($zip->getFromName('a.txt') === str_repeat('a', 100000));
var_dump($zip->getFromName('b.txt') === str_repeat('b', 100000));
$zip->close();
var_dump($zip->open($nextFilename, ZipArchive::CHECKCONS));
var_dump($zip->numFiles);
var_dump($zip->getFromName('new.txt') === 'new contents');
$zip->close();
?>
--CLEAN--
<?php
@unlink(__DIR__ . '/zip_close_mutator_reentry_open.zip');
@unlink(__DIR__ . '/zip_close_mutator_reentry_open_next.zip');
?>
--EXPECT--
deleteIndex: Error: Already being closed
addFromString: Error: Already being closed
registerProgressCallback: Error: Already being closed
bool(true)
bool(true)
bool(true)
bool(true)
int(2)
bool(true)
bool(true)
bool(true)
int(1)
bool(true)

A progress or cancel callback runs inside zip_close() after libzip has
fixed the list of entries it writes. Deleting or unchanging an entry from
the callback frees a dirent that zip_close() still uses, and other
changes are either dropped or make the close fail and lose the archive.
Throw the Error that close() and open() already raise in that state from
every method that modifies the archive.
@iliaal
iliaal force-pushed the fix/aph-zip-close-mutator-reentry-v0oc-84-work branch from 831fe15 to dd200bb Compare October 4, 2026 14:29
@iliaal

iliaal commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

Thanks, added both

@LamentXU123 LamentXU123 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Please leave this to me I want to check this again before I merge.

LamentXU123 added a commit that referenced this pull request Oct 8, 2026
* PHP-8.6:
  ext/zip: Reject ZipArchive mutators during close() (#24025)
@LamentXU123

Copy link
Copy Markdown
Member

Thanks!

damek24 pushed a commit to damek24/php-src that referenced this pull request Oct 8, 2026
* PHP-8.4:
  ext/zip: Reject ZipArchive mutators during close() (php#24025)
damek24 pushed a commit to damek24/php-src that referenced this pull request Oct 8, 2026
* PHP-8.5:
  ext/zip: Reject ZipArchive mutators during close() (php#24025)
arnaud-lb added a commit to frodeborli/php-src that referenced this pull request Oct 9, 2026
* up/master: (180 commits)
  Changed the test expected result of `pdo_mysql/bug76815_pdo_mysql_f to %d (php#13808)
  ext/standard: name the real parameter in the unpack() offset error (php#24215)
  ext/readline: Refactor CLI readline completion generators
  Fix phpGH-24081: User opcode DISPATCH runs on a stale frame in the TAILCALL VM
  ext/standard: Validate the bcrypt cost before reading it
  JIT: Avoid object type check if the object is known to be a type (php#24086)
  zend_alloc: move a small block shrunk to the size of the bin below
  Fix phpGH-23979: Nullsafe operator must not flush delayed oplines of an enclosing function
  ext/zip: Reject ZipArchive mutators during close() (php#24025)
  Fix OSS-Fuzz #568005340: FETCH_DIM_FUNC_ARG partial conversion
  Fix too wide type inference for ASSIGN_DIM_OP
  Fix type inference of ADD_ARRAY_UNPACK with integer keys
  Evaluate ZEND_SPACESHIP in SCCP
  Add range inference for SPACESHIP
  JIT: Optimize array checks in comparisons (php#24084)
  Fix leak when the added previous exception is already in the chain (php#24177)
  date: Add `php_date_time_duration_create()` in a new `time_duration.h` (php#24072)
  ext/zip: Fix use-after-free in the archive destructor path (php#23779)
  ext/standard: Optimize array_chunk() by filling packed chunks directly
  Fix phpGH-17626: JIT corrupts opline handler when blacklisting root trace
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants