Bug #68933 [Opn]: Invalid read of size 8 in zend_std_read_property

From: Date: Sat, 31 Jan 2015 09:11:17 +0000
Subject: Bug #68933 [Opn]: Invalid read of size 8 in zend_std_read_property
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190363@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68933&edit=1 ID: 68933 Updated by: laruence@php.net Reported by: arjen at react dot com Summary: Invalid read of size 8 in zend_std_read_property Status: Open Type: Bug Package: Scripting Engine problem Operating System: Linux PHP Version: master-Git-2015-01-28 (Git) -Assigned To: +Assigned To: dmitry Block user comment: N Private report: N New Comment: a fix could be: https://gist.github.com/laruence/31d0bbbef990bb548520 but this introuced a new hash lookup, seems a little expensive... Previous Comments: ------------------------------------------------------------------------ [2015-01-30 13:11:20] arjen at react dot com Too some time, but I've created a testcase! See https://gist.github.com/arjenschol/3d94195ca51aa44db1c6 It happens when a guard is in active, and a new guard on the same object requires a hashtable resize. So you need to put some guards to trigger the resize. It's for the first part. The php_pcre_exec part causes the segfault is unknown. ------------------------------------------------------------------------ [2015-01-29 14:15:52] arjen at react dot com Sorry, testsuite.php is an internal testsuite which I cannot provide. I understand it's difficult to debug this without testcase. If I can provide anything which makes it easier to debug, please ask. I'll try to create a separate testcase, but I don't know if that's possible. ------------------------------------------------------------------------ [2015-01-28 15:54:02] laruence@php.net where couldI get the testsuite.php? ------------------------------------------------------------------------ [2015-01-28 13:04:32] arjen at react dot com Description: ------------ Running complete testsuite with valgrind (USE_ZEND_ALLOC=0 valgrind --vgdb-error=1 --track-origins=yes --leak-check=full php-src/sapi/cli/php testsuite.php) gives following error: ==27978== Invalid read of size 8 ==27978== at 0x97C7E7: zend_std_read_property (zend_object_handlers.c:540) ==27978== by 0x9ACB6A: ZEND_FETCH_OBJ_R_SPEC_VAR_CONST_HANDLER (zend_vm_execute.h:13108) ==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352) ==27978== by 0x98EE83: zend_execute (zend_vm_execute.h:381) ==27978== by 0x941C8C: zend_execute_scripts (zend.c:1271) ==27978== by 0x8B8BEA: php_execute_script (main.c:2554) ==27978== by 0x9E512E: do_cli (php_cli.c:982) ==27978== by 0x9E60D7: main (php_cli.c:1361) ==27978== Address 0xd34a220 is 480 bytes inside a block of size 576 free'd ==27978== at 0x4C2C29E: realloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==27978== by 0x9121D8: _erealloc (zend_alloc.c:2219) ==27978== by 0x9123D3: _safe_erealloc (zend_alloc.c:2257) ==27978== by 0x953B41: zend_hash_do_resize (zend_hash.c:573) ==27978== by 0x95296E: _zend_hash_add_or_update_i (zend_hash.c:299) ==27978== by 0x952BFF: _zend_hash_add_new (zend_hash.c:343) ==27978== by 0x97C54C: zend_get_property_guard (zend_object_handlers.c:490) ==27978== by 0x97C73B: zend_std_read_property (zend_object_handlers.c:532) ==27978== by 0x9ACB6A: ZEND_FETCH_OBJ_R_SPEC_VAR_CONST_HANDLER (zend_vm_execute.h:13108) ==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352) ==27978== by 0x92A5E8: zend_call_function (zend_execute_API.c:835) ==27978== by 0x965853: zend_call_method (zend_interfaces.c:101) After this error another error is triggered and ends with a segfault: ==27978== Invalid write of size 8 ==27978== at 0x97C7F5: zend_std_read_property (zend_object_handlers.c:540) ==27978== by 0x9ACB6A: ZEND_FETCH_OBJ_R_SPEC_VAR_CONST_HANDLER (zend_vm_execute.h:13108) ==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352) ==27978== by 0x98EE83: zend_execute (zend_vm_execute.h:381) ==27978== by 0x941C8C: zend_execute_scripts (zend.c:1271) ==27978== by 0x8B8BEA: php_execute_script (main.c:2554) ==27978== by 0x9E512E: do_cli (php_cli.c:982) ==27978== by 0x9E60D7: main (php_cli.c:1361) ==27978== Address 0xd34a220 is 480 bytes inside a block of size 576 free'd ==27978== at 0x4C2C29E: realloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==27978== by 0x9121D8: _erealloc (zend_alloc.c:2219) ==27978== by 0x9123D3: _safe_erealloc (zend_alloc.c:2257) ==27978== by 0x953B41: zend_hash_do_resize (zend_hash.c:573) ==27978== by 0x95296E: _zend_hash_add_or_update_i (zend_hash.c:299) ==27978== by 0x952BFF: _zend_hash_add_new (zend_hash.c:343) ==27978== by 0x97C54C: zend_get_property_guard (zend_object_handlers.c:490) ==27978== by 0x97C73B: zend_std_read_property (zend_object_handlers.c:532) ==27978== by 0x9ACB6A: ZEND_FETCH_OBJ_R_SPEC_VAR_CONST_HANDLER (zend_vm_execute.h:13108) ==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352) ==27978== by 0x92A5E8: zend_call_function (zend_execute_API.c:835) ==27978== by 0x965853: zend_call_method (zend_interfaces.c:101) ==27978== ==27978== (action on error) vgdb me ... ==27978== Invalid read of size 1 ==27978== at 0x41C7814: ??? ==27978== by 0x4EF798: _pcre_jit_exec (pcre_jit_compile.c:10433) ==27978== by 0x4BC8A9: php_pcre_exec (pcre_exec.c:6487) ==27978== by 0x4F265F: php_pcre_match_impl (php_pcre.c:679) ==27978== by 0x4F225B: php_do_pcre_match (php_pcre.c:565) ==27978== by 0x4F3445: zif_preg_match (php_pcre.c:895) ==27978== by 0x98F788: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596) ==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352) ==27978== by 0x92A5E8: zend_call_function (zend_execute_API.c:835) ==27978== by 0x965853: zend_call_method (zend_interfaces.c:101) ==27978== by 0x965F20: zend_user_it_rewind (zend_interfaces.c:242) ==27978== by 0x9A823B: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11903) ==27978== Address 0xffffffffffffffc4 is not stack'd, malloc'd or (recently) free'd ==27978== ==27978== (action on error) vgdb me ... ==27978== Continuing ... ==27978== ==27978== Process terminating with default action of signal 11 (SIGSEGV) ==27978== Access not within mapped region at address 0xFFFFFFFFFFFFFFC4 ==27978== at 0x41C7814: ??? ==27978== by 0x4EF798: _pcre_jit_exec (pcre_jit_compile.c:10433) ==27978== by 0x4BC8A9: php_pcre_exec (pcre_exec.c:6487) ==27978== by 0x4F265F: php_pcre_match_impl (php_pcre.c:679) ==27978== by 0x4F225B: php_do_pcre_match (php_pcre.c:565) ==27978== by 0x4F3445: zif_preg_match (php_pcre.c:895) ==27978== by 0x98F788: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596) ==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352) ==27978== by 0x92A5E8: zend_call_function (zend_execute_API.c:835) ==27978== by 0x965853: zend_call_method (zend_interfaces.c:101) ==27978== by 0x965F20: zend_user_it_rewind (zend_interfaces.c:242) ==27978== by 0x9A823B: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11903) Test script: --------------- No simple testcase available. Expected result: ---------------- No memory errors or segfault. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68933&edit=1

« previous php.bugs (#190363) next »