Bug #66429 [NEW]: Logic flaw in handling of empty Interned strings

From: Date: Mon, 06 Jan 2014 23:27:17 +0000
Subject: Bug #66429 [NEW]: Logic flaw in handling of empty Interned strings
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183615@lists.php.net to get a copy of this message
From:             Terry at ellisons dot org dot uk
Operating system: N/A
PHP version:      master-Git-2014-01-06 (Git)
Package:          opcache
Bug Type:         Bug
Bug description:Logic flaw in handling of empty Interned strings

Description:
------------
The opcache extenstion turns off PHP string interning and substitutes
its own strategy for collecting interned strings in its own SHM-based
interned_strings hash during  in ZendAcclerator.c:zend_accel_init_shm().
 It is then turned off in accel_shutdown().

Before and after these points in accel_startup() and accel_shutdown(),
all interned strings created and dtored should lie between the original
CG(interned_strings_start) and CG(interned_strings_end).  Note that this
list of local interned strings is non-trivial (typically some 2,000)
comprising interned_string representations of all builtin Zend and
extension constants, function names and methods. I call these built-in
interned strings.  

Between these same points all interned strings created and dtored should
lie between ZCSG(interned_strings_start) and ZCSG(interned_strings_end).
 I call these shared interned strings.

However, if a zval refering to a builtin interned string is dtored
between accel_startup() and accel_shutdown(), then the !IS_INTERNED()
macro will return false as the address of the string lies between
original CG(interned_strings_start) and CG(interned_strings_end) and not
between   
ZCSG(interned_strings_start) and ZCSG(interned_strings_end).  DTOR will
then attempt to efree the string which is invalid as the string wasn't
emalloc'ed.

As long as the scope and lifetimes of the two sets of interned strings
are disjoint this all works fine.  However, one optimization introduced
in PHP-5.6 has been missed and that is with strings and zvals created
with the STR_EMPTY_ALLOC(), RETVAL_EMPTY_STRING() and
ZVAL_EMPTY_STRING() macros.  These are all based on the
CG(interned_empty_string) value and this is a built-in interned string. 
If any of these are DTORed then the dtor will fail as described above. 
ZendAccelerator should establish its own ZCSG(interned_empty_string)
value to prevent this happening.


Test script:
---------------
php56 -r '' 

(with opcache enabled)


-- 
Edit bug report at https://bugs.php.net/bug.php?id=66429&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=66429&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=66429&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=66429&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=66429&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=66429&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=66429&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=66429&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=66429&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=66429&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=66429&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=66429&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=66429&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=66429&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=66429&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=66429&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=66429&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=66429&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=66429&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=66429&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=66429&r=mysqlcfg



Thread (3 messages)

« previous php.bugs (#183615) next »