Bug #69579 [Com]: Invalid free in extension trait

From: Date: Tue, 07 Jul 2015 17:30:18 +0000
Subject: Bug #69579 [Com]: Invalid free in extension trait
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194182@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69579&edit=1

 ID:                 69579
 Comment by:         jbboehr at gmail dot com
 Reported by:        jbboehr at gmail dot com
 Summary:            Invalid free in extension trait
 Status:             Open
 Type:               Bug
 Package:            Unknown/Other Function
 Operating System:   Ubuntu 14.04
 PHP Version:        master-Git-2015-05-06 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

I found a hack-ey workaround, so previous commit can reproduce:
https://github.com/jbboehr/php-psr/commit/a21297aabb936b7b0c22b4cc216affbc99f3be33


Previous Comments:
------------------------------------------------------------------------
[2015-05-06 02:20:01] jbboehr at gmail dot com

Description:
------------
Tangentially related to https://bugs.php.net/bug.php?id=69566

I've been working on a PHP extension that includes a trait: https://github.com/jbboehr/php-psr/tree/php7

On git master, I get a sigabort.

I'm not sure why normal traits don't get the invalid free; maybe they're all
allocated by arena.

In zend_add_trait_method, the internal function struct is not the same size as a user function, so
valgrind outputs an invalid read warning.

As an aside, assuming allowing traits in an extension is something that should be supported, it
might be ideal to have at least one internal trait somewhere to catch these sort of issues, but
that's outside the scope of this bug report.

Test script:
---------------
Unfortunately, it's in an extension, so to reproduce compile https://github.com/jbboehr/php-psr/tree/php7
and run
TEST_PHP_ARGS=-m make test

Actual result:
--------------
Valgrind output:

==15151== Invalid read of size 8
==15151==    at 0x8FA68D: zend_traits_copy_functions (zend_inheritance.c:1184)
==15151==    by 0x8FB15F: zend_do_traits_method_binding (zend_inheritance.c:1387)
==15151==    by 0x8FBA08: zend_do_bind_traits (zend_inheritance.c:1588)
==15151==    by 0x907AD1: ZEND_BIND_TRAITS_SPEC_HANDLER (zend_vm_execute.h:1451)
==15151==    by 0x903F0F: execute_ex (zend_vm_execute.h:394)
==15151==    by 0x9040D3: zend_execute (zend_vm_execute.h:434)
==15151==    by 0x8A73B4: zend_execute_scripts (zend.c:1389)
==15151==    by 0x7F79CA: php_execute_script (main.c:2468)
==15151==    by 0x972711: do_cli (php_cli.c:967)
==15151==    by 0x973A30: main (php_cli.c:1334)
==15151==  Address 0xd919a70 is 0 bytes after a block of size 64 alloc'd
==15151==    at 0x4C2AB80: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==15151==    by 0x8B1B93: zend_register_functions (zend_API.c:2272)
==15151==    by 0x8B31C1: do_register_internal_class (zend_API.c:2687)
==15151==    by 0x8B33AD: zend_register_internal_class (zend_API.c:2735)
==15151==    by 0xE247F2E: php_psr_register_LoggerTrait (psr.c:308)
==15151==    by 0xE24823C: zm_startup_psr (psr.c:360)
==15151==    by 0x8B0362: zend_startup_module_ex (zend_API.c:1878)
==15151==    by 0x8B03E0: zend_startup_module_zval (zend_API.c:1893)
==15151==    by 0x8BE50F: zend_hash_apply (zend_hash.c:1437)
==15151==    by 0x8B09F7: zend_startup_modules (zend_API.c:2004)
==15151==    by 0x7F6ECD: php_module_startup (main.c:2190)
==15151==    by 0x97136A: php_cli_startup (php_cli.c:419)
==15151== 
==15151== Invalid free() / delete / delete[] / realloc()
==15151==    at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==15151==    by 0x892466: zend_function_dtor (zend_opcode.c:128)
==15151==    by 0x8BDA20: zend_hash_destroy (zend_hash.c:1182)
==15151==    by 0x892DD5: destroy_zend_class (zend_opcode.c:285)
==15151==    by 0x8BD103: _zend_hash_del_el_ex (zend_hash.c:938)
==15151==    by 0x8BD1E3: _zend_hash_del_el (zend_hash.c:962)
==15151==    by 0x8BE978: zend_hash_reverse_apply (zend_hash.c:1532)
==15151==    by 0x88BFFF: shutdown_executor (zend_execute_API.c:351)
==15151==    by 0x8A5C7A: zend_deactivate (zend.c:964)
==15151==    by 0x7F60C1: php_request_shutdown (main.c:1806)
==15151==    by 0x973110: do_cli (php_cli.c:1135)
==15151==    by 0x973A30: main (php_cli.c:1334)
==15151==  Address 0xd9bb498 is 4,568 bytes inside a block of size 65,536 alloc'd
==15151==    at 0x4C2AB80: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==15151==    by 0x86E752: _emalloc (zend_alloc.c:2195)
==15151==    by 0x870240: zend_arena_create (zend_arena.h:36)
==15151==    by 0x8714A1: init_compiler (zend_compile.c:324)
==15151==    by 0x8A5ACD: zend_activate (zend.c:940)
==15151==    by 0x7F4F3D: php_request_startup (main.c:1564)
==15151==    by 0x972542: do_cli (php_cli.c:938)
==15151==    by 0x973A30: main (php_cli.c:1334)
==15151== 



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69579&edit=1


Thread (5 messages)

« previous php.bugs (#194182) next »