Bug #66609 [Asn]: php crashes with __get() and ++ operator in some cases
| From: | laruence@php.net | Date: | Fri, 06 Mar 2015 09:27:34 +0000 |
| Subject: | Bug #66609 [Asn]: php crashes with __get() and ++ operator in some cases | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-191205@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66609&edit=1
ID: 66609
Updated by: laruence@php.net
Reported by: drewparoski at gmail dot com
Summary: php crashes with __get() and ++ operator in some
cases
Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: CentOS Linux 6.3
PHP Version: 5.5.8
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
A more simple fix could be:
diff --git a/Zend/zend_vm_def.h b/Zend/zend_vm_def.h
index a795a75..5945452 100644
--- a/Zend/zend_vm_def.h
+++ b/Zend/zend_vm_def.h
@@ -754,6 +754,7 @@ ZEND_VM_HELPER_EX(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMP|VAR
}
z = value;
}
+ object = *object_ptr;
ZVAL_COPY_VALUE(retval, z);
zendi_zval_copy_ctor(*retval);
ALLOC_ZVAL(z_copy);
thanks
Previous Comments:
------------------------------------------------------------------------
[2015-03-06 09:05:42] laruence@php.net
A quick fix could be:
diff --git a/Zend/zend_vm_def.h b/Zend/zend_vm_def.h
index a795a75..3b32af4 100644
--- a/Zend/zend_vm_def.h
+++ b/Zend/zend_vm_def.h
@@ -741,9 +741,20 @@ ZEND_VM_HELPER_EX(zend_post_incdec_property_helper, VAR|UNUSED|CV,
CONST|TMP|VAR
if (!have_get_ptr) {
if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
- zval *z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE ==
IS_CONST)
? opline->op2.literal : NULL) TSRMLS_CC);
+ zval *obj_copy;
+ zval *z;
zval *z_copy;
+ if (!Z_ISREF_P(object)) {
+ ALLOC_ZVAL(obj_copy);
+ INIT_PZVAL_COPY(obj_copy, object);
+ zendi_zval_copy_ctor(*obj_copy);
+ object = obj_copy;
+ } else {
+ Z_ADDREF_P(object);
+ }
+ z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ?
opli
ne->op2.literal : NULL) TSRMLS_CC);
+
if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
zval *value = Z_OBJ_HT_P(z)->get(z TSRMLS_CC);
@@ -762,6 +773,7 @@ ZEND_VM_HELPER_EX(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMP|VAR
incdec_op(z_copy);
Z_ADDREF_P(z);
Z_OBJ_HT_P(object)->write_property(object, property, z_copy, ((OP2_TYPE == IS_CONST) ?
opline->o
p2.literal : NULL) TSRMLS_CC);
+ zval_ptr_dtor(&object);
zval_ptr_dtor(&z_copy);
zval_ptr_dtor(&z);
I assume the similar issue also exists in __set
anyway, I need do some verifing before commit the fix.
thanks
------------------------------------------------------------------------
[2015-02-17 01:32:38] vort dot fu at gmail dot com
definitely not recursion related.
(gdb) r poc-php-66609.php 0x12345678
Starting program: /Users/vortfu/Downloads/php-5.6.5/sapi/cli/php poc-php-66609.php 0x12345678
Program received signal EXC_BAD_ACCESS, Could not access memory.
Reason: KERN_INVALID_ADDRESS at address: 0x0000000012345678
------------------------------------------------------------------------
[2014-02-04 01:38:53] drewparoski at gmail dot com
Verified this happens on PHP 5.5.8, which is the current official release. Updated the version
number for this bug accordingly, though it's worth noting this bug still happens on PHP
5.6.0alpha1 as well.
------------------------------------------------------------------------
[2014-01-30 08:56:02] drewparoski at gmail dot com
If you add an echo statement to each __get() method, you can see that Bar::__get() and Foo::__get()
collectively only get called 3 times before the crash happens. So I don't think the php process
is crashing because of stack overflow in this case. Looking at the faulting machine instruction in
gdb (which tries to dereference $rax when it is 0), I think that either Z_OBJ_HT_P(object) is null
or Z_OBJ_HT_P(object)->write_property is null for some reason.
------------------------------------------------------------------------
[2014-01-30 06:20:11] krakjoe@php.net
looks an awful look like infinite recursion to me ...
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=66609
--
Edit this bug report at https://bugs.php.net/bug.php?id=66609&edit=1