Bug #69154 [Opn]: Access violation in php7.dll!_emalloc

From: Date: Mon, 02 Mar 2015 14:52:51 +0000
Subject: Bug #69154 [Opn]: Access violation in php7.dll!_emalloc
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191045@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69154&edit=1

 ID:                 69154
 User updated by:    mberchtold at gmail dot com
 Reported by:        mberchtold at gmail dot com
 Summary:            Access violation in php7.dll!_emalloc
 Status:             Open
 Type:               Bug
 Package:            *General Issues
 Operating System:   Windows Server 2012 R2
 PHP Version:        master-Git-2015-03-01 (snap)
 Block user comment: N
 Private report:     N

 New Comment:

If I had to make a guess I would say the mail function somehow corrupts the heap/memory management
and that is the reason that a following call to _emalloc causes the access violation.

As soon as I uncomment the call to mail I do not experience the access violation.


Previous Comments:
------------------------------------------------------------------------
[2015-03-02 14:36:58] mberchtold at gmail dot com

The pdb are matching in today's x86 snapshot and I was able to reproduce the crash with x86.
The result is a more meaning stack trace:

 	php7.dll!_emalloc(unsigned int size) Line 2200	C
>	php7.dll!lex_scan(_zval_struct * zendlval) Line 1919	C
 	php7.dll!zendlex(_zend_parser_stack_elem * elem) Line 1382	C
 	php7.dll!zendparse() Line 4341	C
 	php7.dll!compile_file(_zend_file_handle * file_handle, int type) Line 592	C
 	php7.dll!phar_compile_file(_zend_file_handle * file_handle, int type) Line 3311	C
 	php_opcache.dll!compile_and_cache_file(_zend_file_handle * file_handle, int type, char * key,
unsigned int key_length, _zend_op_array * * op_array_p, int * from_shared_memory) Line 1392	C
 	php_opcache.dll!persistent_compile_file(_zend_file_handle * file_handle, int type) Line 1611	C
 	php7.dll!compile_filename(int type, _zval_struct * filename) Line 640	C
 	php7.dll!ZEND_INCLUDE_OR_EVAL_SPEC_CV_HANDLER(_zend_execute_data * execute_data) Line 24729	C
 	php7.dll!execute_ex(_zend_execute_data * execute_data) Line 352	C
 	php7.dll!zend_call_function(_zend_fcall_info * fci, _zend_fcall_info_cache * fci_cache) Line 847	C
 	php7.dll!zend_call_method(_zval_struct * object, _zend_class_entry * obj_ce, _zend_function * *
fn_proxy, const char * function_name, unsigned int function_name_len, _zval_struct * retval_ptr, int
param_count, _zval_struct * arg1, _zval_struct * arg2) Line 101	C
 	php7.dll!zif_spl_autoload_call(_zend_execute_data * execute_data, _zval_struct * return_value)
Line 426	C
 	php7.dll!zend_call_function(_zend_fcall_info * fci, _zend_fcall_info_cache * fci_cache) Line 866	C
 	php7.dll!zend_lookup_class_ex(_zend_string * name, const _zval_struct * key, int use_autoload)
Line 1029	C
 	php7.dll!zend_fetch_class_by_name(_zend_string * class_name, const _zval_struct * key, int
fetch_type) Line 1343	C
 	php7.dll!ZEND_NEW_SPEC_CONST_HANDLER(_zend_execute_data * execute_data) Line 2881	C
 	php7.dll!execute_ex(_zend_execute_data * execute_data) Line 352	C
 	php7.dll!zend_call_function(_zend_fcall_info * fci, _zend_fcall_info_cache * fci_cache) Line 847	C
 	php7.dll!zif_call_user_func(_zend_execute_data * execute_data, _zval_struct * return_value) Line
4725	C
 	php7.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data * execute_data) Line 649	C
 	php7.dll!execute_ex(_zend_execute_data * execute_data) Line 352	C
 	php7.dll!zend_call_function(_zend_fcall_info * fci, _zend_fcall_info_cache * fci_cache) Line 847	C
 	php7.dll!zif_call_user_func(_zend_execute_data * execute_data, _zval_struct * return_value) Line
4725	C
 	php7.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data * execute_data) Line 649	C
 	php7.dll!execute_ex(_zend_execute_data * execute_data) Line 352	C
 	php7.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value) Line 381	C
 	php7.dll!zend_execute_scripts(int type, _zval_struct * retval, int file_count, ...) Line 1310	C
 	php7.dll!php_execute_script(_zend_file_handle * primary_file) Line 2527	C
 	php-cgi.exe!main(int argc, char * * argv) Line 2439	C
 	php-cgi.exe!__tmainCRTStartup() Line 536	C
 	kernel32.dll!@BaseThreadInitThunk@12()	Unknown
 	ntdll.dll!__RtlUserThreadStart()	Unknown
 	ntdll.dll!__RtlUserThreadStart@8()	Unknown

I have sent the dump by email as well.

------------------------------------------------------------------------
[2015-03-02 13:15:13] mberchtold at gmail dot com

I have sent the crash dump by email.

------------------------------------------------------------------------
[2015-03-02 09:53:30] ab@php.net

First of all, please check with bug #69115. Recently an issue with mail() was fixed.

Secondly, I see a potential issue in the bt supplied. call_user_func() seems to be called
recursively and that can lead to the stack overflow. PHP has no recursion protection for this case.
Please check the script. If that's the case, there'll be probably no need to share the
dump. Otherwise, please send a mail with the link to the dump.

Thanks.

------------------------------------------------------------------------
[2015-03-01 22:09:25] mberchtold at gmail dot com

Description:
------------
The crash happens in a call to the mail function

stack trace:
>	php7.dll!_emalloc(unsigned __int64 size) Line 2200	C
 	php7.dll!zend_objects_new(_zend_class_entry * ce) Line 142	C
 	php7.dll!_object_and_properties_init(_zval_struct * arg, _zend_class_entry * class_type,
_zend_array * properties) Line 1106	C
 	php7.dll!ZEND_NEW_SPEC_CONST_HANDLER(_zend_execute_data * execute_data) Line 2885	C
 	php7.dll!execute_ex(_zend_execute_data * execute_data) Line 352	C
 	php7.dll!zend_call_function(_zend_fcall_info * fci, _zend_fcall_info_cache * fci_cache) Line 848	C
 	php7.dll!zif_call_user_func(_zend_execute_data * execute_data, _zval_struct * return_value) Line
4725	C
 	php7.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data * execute_data) Line 649	C
 	php7.dll!execute_ex(_zend_execute_data * execute_data) Line 352	C
 	php7.dll!zend_call_function(_zend_fcall_info * fci, _zend_fcall_info_cache * fci_cache) Line 848	C
 	php7.dll!zif_call_user_func(_zend_execute_data * execute_data, _zval_struct * return_value) Line
4725	C
 	php7.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data * execute_data) Line 649	C
 	php7.dll!execute_ex(_zend_execute_data * execute_data) Line 352	C
 	php7.dll!zend_call_function(_zend_fcall_info * fci, _zend_fcall_info_cache * fci_cache) Line 848	C
 	php7.dll!zif_call_user_func(_zend_execute_data * execute_data, _zval_struct * return_value) Line
4725	C
 	php7.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data * execute_data) Line 649	C
 	php7.dll!execute_ex(_zend_execute_data * execute_data) Line 352	C
 	php7.dll!zend_call_function(_zend_fcall_info * fci, _zend_fcall_info_cache * fci_cache) Line 848	C
 	php7.dll!zif_call_user_func(_zend_execute_data * execute_data, _zval_struct * return_value) Line
4725	C
 	php7.dll!ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER(_zend_execute_data * execute_data) Line 649	C
 	php7.dll!execute_ex(_zend_execute_data * execute_data) Line 352	C
 	php7.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value) Line 381	C
 	php7.dll!zend_execute_scripts(int type, _zval_struct * retval, int file_count, ...) Line 1283	C
 	php7.dll!php_execute_script(_zend_file_handle * primary_file) Line 2527	C
 	php-cgi.exe!main(int argc, char * * argv) Line 2488	C
 	php-cgi.exe!__tmainCRTStartup() Line 536	C
 	kernel32.dll!BaseThreadInitThunk()	Unknown
 	ntdll.dll!RtlUserThreadStart()	Unknown

The full crash dump is available on request by email.

Snapshot: php-master-nts-windows-vc11-x64-r9dac923

The access violation also happens with the php x86 snapshot as well but the debug symbols are not
matching.



Test script:
---------------
unable to provide a test script. But crash is reproducible. Crash happens in a call to mail


Expected result:
----------------
no access violation?

Actual result:
--------------
access violation


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69154&edit=1


Thread (11 messages)

« previous php.bugs (#191045) next »