Bug #70157 [Com]: parse_ini_string() segmentation fault with INI_SCANNER_TYPED

From: Date: Fri, 07 Aug 2015 04:02:15 +0000
Subject: Bug #70157 [Com]: parse_ini_string() segmentation fault with INI_SCANNER_TYPED
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194994@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70157&edit=1

 ID:                 70157
 Comment by:         datibbaw@php.net
 Reported by:        publikusmail at postafiok dot hu
 Summary:            parse_ini_string() segmentation fault with
                     INI_SCANNER_TYPED
 Status:             Verified
 Type:               Bug
 Package:            Filesystem function related
 Operating System:   *
 PHP Version:        php-5.6
 Assigned To:        datibbaw
 Block user comment: N
 Private report:     N

 New Comment:

Sorry for the delay, I'll have a look!


Previous Comments:
------------------------------------------------------------------------
[2015-08-07 03:30:33] pierrick@php.net

An other segfault due to the same problem:

$ini = "foo[1] = bar";
var_dump(parse_ini_string($ini, true, INI_SCANNER_TYPED));

------------------------------------------------------------------------
[2015-07-29 03:12:36] laruence@php.net

actually, this is introduced in 5.6, not a php7 specific issue. 

@datibbaw, could you please have a look ?

------------------------------------------------------------------------
[2015-07-28 19:32:37] cmb@php.net

Confirmed:

Program received signal SIGSEGV, Segmentation fault.
0x00000000005e78e2 in zend_ini_add_string (result=0x7fffffff9cd0,
    op1=0x7fffffff9d20, op2=0x7fffffff9d30)
    at /home/cmb/php-src/Zend/zend_ini_parser.y:105
105             int op1_len = (int)Z_STRLEN_P(op1);
(gdb) bt
#0  0x00000000005e78e2 in zend_ini_add_string (result=0x7fffffff9cd0,
    op1=0x7fffffff9d20, op2=0x7fffffff9d30)
    at /home/cmb/php-src/Zend/zend_ini_parser.y:105
#1  0x00000000005e8a40 in ini_parse ()
    at /home/cmb/php-src/Zend/zend_ini_parser.y:348
#2  0x00000000005e7e51 in zend_parse_ini_string (
    str=0x7ffff687f070 "\n\n[agatha.christie]\ntitle = 10 little indians\n\n", u
nbuffered_errors=0 '\000', scanner_mode=2,
    ini_parser_cb=0x526878 <php_ini_parser_cb_with_sections>,
    arg=0x7ffff68130b0) at /home/cmb/php-src/Zend/zend_ini_parser.y:238
#3  0x0000000000526bf8 in zif_parse_ini_string (execute_data=0x7ffff6813140,
    return_value=0x7ffff68130b0)
    at /home/cmb/php-src/ext/standard/basic_functions.c:5957
    
The problem is obvious. op1 in zend_ini_add_string is IS_LONG,
but is treated as IS_STRING. The solution, however, is not so
obvious to me.

------------------------------------------------------------------------
[2015-07-28 12:31:25] publikusmail at postafiok dot hu

Description:
------------
This bug affects both parse_ini_file() and parse_ini_string() functions.

A string value starting with a number and without quotes causes segmentation fault, whenever mode is
set to INI_SCANNER_TYPED.

PHP versions tested: 5.6.9, 7.0.0b2
OS tested: Debian 8.1, Windows 8.1

Test script:
---------------
<?php

$ini = "

[agatha.christie]
title = 10 little indians

";

var_dump(parse_ini_string($ini, true, INI_SCANNER_TYPED));

?>

Expected result:
----------------
array(1) {
  ["agatha.christie"]=>
  array(1) {
    ["title"]=>
    string(17) "10 little indians"
  }
}

Actual result:
--------------
segmentation fault


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70157&edit=1


Thread (6 messages)

« previous php.bugs (#194994) next »