Bug #69788 [Opn->Nab]: Malformed script causes Uncaught EngineException in php-cgi, valgrind SIGILL
| From: | requinix@php.net | Date: | Tue, 09 Jun 2015 20:22:32 +0000 |
| Subject: | Bug #69788 [Opn->Nab]: Malformed script causes Uncaught EngineException in php-cgi, valgrind SIGILL | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193264@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69788&edit=1
ID: 69788
Updated by: requinix@php.net
Reported by: brian dot carpenter at gmail dot com
Summary: Malformed script causes Uncaught EngineException in
php-cgi, valgrind SIGILL
-Status: Open
+Status: Not a bug
Type: Bug
Package: Reproducible crash
Operating System: Debian 7
PHP Version: master-Git-2015-06-09 (Git)
Block user comment: N
Private report: N
New Comment:
The "malformed script" isn't. Not in PHP 7. The Uniform Variable Syntax changes allow
it and the code is equivalent to
$f = array(t . array()); // array("tArray") with notices
0 / $f();
http://3v4l.org/I5RIC (slightly modified)
https://wiki.php.net/rfc/uniform_variable_syntax
PHP 7 also starts a switch to exceptions instead of errors, which is why you're seeing the
EngineException (subject to change) instead of a regular parse error.
https://wiki.php.net/rfc/engine_exceptions_for_php7
That leaves the valgrind problem, but that does seem to be a valgrind problem since PHP does run
normally (and under GDB) without problems. Make sure you're using the most recent version of
valgrind, but if that doesn't resolve it then I suggest making a bug report there. Remember
that PHP 7 is still in development so binaries may/will change.
Previous Comments:
------------------------------------------------------------------------
[2015-06-09 19:46:23] brian dot carpenter at gmail dot com
Description:
------------
While fuzzing the latest PHP built from git source with AFL (http://lcamtuf.coredump.cx/afl/), I
came across this bug.
geeknik@h9n1:~$ ~/php-src/sapi/cgi/php-cgi -v
PHP 7.0.0-dev (cgi-fcgi) (built: Jun 8 2015 12:00:13)
Copyright (c) 1997-2015 The PHP Group
Zend Engine v3.0.0-dev, Copyright (c) 1998-2015 Zend Technologies
Test script:
---------------
<?0/array(t.array())();
https://www.dropbox.com/s/msw5h4k4qaq2icg/test00-min?dl=0
Expected result:
----------------
PHP v5.4.41-0+deb7u1 (cli) returns the following:
PHP Parse error: syntax error, unexpected '(' in
/home/geeknik/php-tmp/out/fuzzer01/crashes/test00-min on line 1
Actual result:
--------------
Valgrind:
vex amd64->IR: unhandled instruction bytes: 0xF3 0x4D 0xF 0xBC 0xE4 0x45 0x1 0xC4
==18903== valgrind: Unrecognised instruction at address 0x1319a3a.
==18903== at 0x1319A3A: zend_mm_alloc_pages (zend_alloc.c:483)
==18903== by 0x131B81C: zend_mm_alloc_small_slow (zend_alloc.c:1190)
==18903== by 0x155F573: virtual_cwd_startup (zend_virtual_cwd.c:431)
==18903== by 0x1412DCC: zend_startup (zend.c:640)
==18903== by 0x11C6F98: php_module_startup (main.c:2066)
==18903== by 0x181CFCC: php_cgi_startup (cgi_main.c:915)
==18903== by 0x43B4AC: main (cgi_main.c:1894)
==18903== Your program just tried to execute an instruction that Valgrind
==18903== did not recognise. There are two possible reasons for this.
==18903== 1. Your program has a bug and erroneously jumped to a non-code
==18903== location. If you are running Memcheck and you just saw a
==18903== warning about a bad jump, it's probably your program's fault.
==18903== 2. The instruction is legitimate but Valgrind doesn't handle it,
==18903== i.e. it's Valgrind's fault. If you think this is the case or
==18903== you are not sure, please let us know and we'll try to fix it.
==18903== Either way, Valgrind will now raise a SIGILL signal which will
==18903== probably kill your program.
==18903==
==18903== Process terminating with default action of signal 4 (SIGILL)
==18903== Illegal opcode at address 0x1319A3A
==18903== at 0x1319A3A: zend_mm_alloc_pages (zend_alloc.c:483)
==18903== by 0x131B81C: zend_mm_alloc_small_slow (zend_alloc.c:1190)
==18903== by 0x155F573: virtual_cwd_startup (zend_virtual_cwd.c:431)
==18903== by 0x1412DCC: zend_startup (zend.c:640)
==18903== by 0x11C6F98: php_module_startup (main.c:2066)
==18903== by 0x181CFCC: php_cgi_startup (cgi_main.c:915)
==18903== by 0x43B4AC: main (cgi_main.c:1894)
Illegal instruction
GDB:
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
X-Powered-By: PHP/7.0.0-dev
Content-type: text/html; charset=UTF-8
<br />
<b>Fatal error</b>: Uncaught EngineException: Function name must be a string in
/home/geeknik/php-tmp/out/fuzzer01/crashes/test00-min:1
Stack trace:
#0 {main}
thrown in <b>/home/geeknik/php-tmp/out/fuzzer01/crashes/test00-min</b> on line
<b>1</b><br />
[Inferior 1 (process 41744) exited with code 0377]
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69788&edit=1