Bug #66609 [Asn->Csd]: php crashes with __get() and ++ operator in some cases

From: Date: Tue, 10 Mar 2015 09:15:22 +0000
Subject: Bug #66609 [Asn->Csd]: php crashes with __get() and ++ operator in some cases
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191279@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66609&edit=1 ID: 66609 Updated by: laruence@php.net Reported by: drewparoski at gmail dot com Summary: php crashes with __get() and ++ operator in some cases -Status: Assigned +Status: Closed Type: Bug Package: Reproducible crash Operating System: CentOS Linux 6.3 PHP Version: 5.5.8 Assigned To: laruence Block user comment: N Private report: N New Comment: Automatic comment on behalf of laruence Revision: http://git.php.net/?p=php-src.git;a=commit;h=6a6c273893178bb9b59c117e31761fe0193d0c9f Log: Fixed bug #66609 (php crashes with __get() and ++ operator in some cases) Previous Comments: ------------------------------------------------------------------------ [2015-03-06 09:27:33] laruence@php.net A more simple fix could be: diff --git a/Zend/zend_vm_def.h b/Zend/zend_vm_def.h index a795a75..5945452 100644 --- a/Zend/zend_vm_def.h +++ b/Zend/zend_vm_def.h @@ -754,6 +754,7 @@ ZEND_VM_HELPER_EX(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMP|VAR } z = value; } + object = *object_ptr; ZVAL_COPY_VALUE(retval, z); zendi_zval_copy_ctor(*retval); ALLOC_ZVAL(z_copy); thanks ------------------------------------------------------------------------ [2015-02-17 01:32:38] vort dot fu at gmail dot com definitely not recursion related. (gdb) r poc-php-66609.php 0x12345678 Starting program: /Users/vortfu/Downloads/php-5.6.5/sapi/cli/php poc-php-66609.php 0x12345678 Program received signal EXC_BAD_ACCESS, Could not access memory. Reason: KERN_INVALID_ADDRESS at address: 0x0000000012345678 ------------------------------------------------------------------------ [2014-02-04 01:38:53] drewparoski at gmail dot com Verified this happens on PHP 5.5.8, which is the current official release. Updated the version number for this bug accordingly, though it's worth noting this bug still happens on PHP 5.6.0alpha1 as well. ------------------------------------------------------------------------ [2014-01-30 08:56:02] drewparoski at gmail dot com If you add an echo statement to each __get() method, you can see that Bar::__get() and Foo::__get() collectively only get called 3 times before the crash happens. So I don't think the php process is crashing because of stack overflow in this case. Looking at the faulting machine instruction in gdb (which tries to dereference $rax when it is 0), I think that either Z_OBJ_HT_P(object) is null or Z_OBJ_HT_P(object)->write_property is null for some reason. ------------------------------------------------------------------------ [2014-01-30 06:20:11] krakjoe@php.net looks an awful look like infinite recursion to me ... ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=66609 -- Edit this bug report at https://bugs.php.net/bug.php?id=66609&edit=1

« previous php.bugs (#191279) next »