From: jbboehr at gmail dot com
Operating system: Ubuntu 14.04
PHP version: master-Git-2015-05-06 (Git)
Package: Unknown/Other Function
Bug Type: Bug
Bug description:Invalid free in extension trait
Description:
------------
Tangentially related to https://bugs.php.net/bug.php?id=69566
I've been working on a PHP extension that includes a trait:
https://github.com/jbboehr/php-psr/tree/php7
On git master, I get a sigabort.
I'm not sure why normal traits don't get the invalid free; maybe they're
all allocated by arena.
In zend_add_trait_method, the internal function struct is not the same
size as a user function, so valgrind outputs an invalid read warning.
As an aside, assuming allowing traits in an extension is something that
should be supported, it might be ideal to have at least one internal
trait somewhere to catch these sort of issues, but that's outside the
scope of this bug report.
Test script:
---------------
Unfortunately, it's in an extension, so to reproduce compile
https://github.com/jbboehr/php-psr/tree/php7
and run
TEST_PHP_ARGS=-m make test
Actual result:
--------------
Valgrind output:
==15151== Invalid read of size 8
==15151== at 0x8FA68D: zend_traits_copy_functions
(zend_inheritance.c:1184)
==15151== by 0x8FB15F: zend_do_traits_method_binding
(zend_inheritance.c:1387)
==15151== by 0x8FBA08: zend_do_bind_traits (zend_inheritance.c:1588)
==15151== by 0x907AD1: ZEND_BIND_TRAITS_SPEC_HANDLER
(zend_vm_execute.h:1451)
==15151== by 0x903F0F: execute_ex (zend_vm_execute.h:394)
==15151== by 0x9040D3: zend_execute (zend_vm_execute.h:434)
==15151== by 0x8A73B4: zend_execute_scripts (zend.c:1389)
==15151== by 0x7F79CA: php_execute_script (main.c:2468)
==15151== by 0x972711: do_cli (php_cli.c:967)
==15151== by 0x973A30: main (php_cli.c:1334)
==15151== Address 0xd919a70 is 0 bytes after a block of size 64
alloc'd
==15151== at 0x4C2AB80: malloc (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==15151== by 0x8B1B93: zend_register_functions (zend_API.c:2272)
==15151== by 0x8B31C1: do_register_internal_class (zend_API.c:2687)
==15151== by 0x8B33AD: zend_register_internal_class
(zend_API.c:2735)
==15151== by 0xE247F2E: php_psr_register_LoggerTrait (psr.c:308)
==15151== by 0xE24823C: zm_startup_psr (psr.c:360)
==15151== by 0x8B0362: zend_startup_module_ex (zend_API.c:1878)
==15151== by 0x8B03E0: zend_startup_module_zval (zend_API.c:1893)
==15151== by 0x8BE50F: zend_hash_apply (zend_hash.c:1437)
==15151== by 0x8B09F7: zend_startup_modules (zend_API.c:2004)
==15151== by 0x7F6ECD: php_module_startup (main.c:2190)
==15151== by 0x97136A: php_cli_startup (php_cli.c:419)
==15151==
==15151== Invalid free() / delete / delete[] / realloc()
==15151== at 0x4C2BDEC: free (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==15151== by 0x892466: zend_function_dtor (zend_opcode.c:128)
==15151== by 0x8BDA20: zend_hash_destroy (zend_hash.c:1182)
==15151== by 0x892DD5: destroy_zend_class (zend_opcode.c:285)
==15151== by 0x8BD103: _zend_hash_del_el_ex (zend_hash.c:938)
==15151== by 0x8BD1E3: _zend_hash_del_el (zend_hash.c:962)
==15151== by 0x8BE978: zend_hash_reverse_apply (zend_hash.c:1532)
==15151== by 0x88BFFF: shutdown_executor (zend_execute_API.c:351)
==15151== by 0x8A5C7A: zend_deactivate (zend.c:964)
==15151== by 0x7F60C1: php_request_shutdown (main.c:1806)
==15151== by 0x973110: do_cli (php_cli.c:1135)
==15151== by 0x973A30: main (php_cli.c:1334)
==15151== Address 0xd9bb498 is 4,568 bytes inside a block of size
65,536 alloc'd
==15151== at 0x4C2AB80: malloc (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==15151== by 0x86E752: _emalloc (zend_alloc.c:2195)
==15151== by 0x870240: zend_arena_create (zend_arena.h:36)
==15151== by 0x8714A1: init_compiler (zend_compile.c:324)
==15151== by 0x8A5ACD: zend_activate (zend.c:940)
==15151== by 0x7F4F3D: php_request_startup (main.c:1564)
==15151== by 0x972542: do_cli (php_cli.c:938)
==15151== by 0x973A30: main (php_cli.c:1334)
==15151==
--
Edit bug report at https://bugs.php.net/bug.php?id=69579&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69579&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69579&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69579&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69579&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69579&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69579&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69579&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69579&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69579&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69579&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69579&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69579&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69579&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69579&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69579&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69579&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69579&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69579&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69579&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69579&r=mysqlcfg