Bug #70262 [Com]: Accessing array crashes PHP 7.0beta3

From: Date: Mon, 17 Aug 2015 12:09:53 +0000
Subject: Bug #70262 [Com]: Accessing array crashes PHP 7.0beta3
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195257@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70262&edit=1

 ID:                 70262
 Comment by:         bugs dot php dot net at majkl578 dot cz
 Reported by:        pavel dot kouril at hotmail dot com
 Summary:            Accessing array crashes PHP 7.0beta3
 Status:             Closed
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Windows, Linux
 PHP Version:        7.0.0beta3
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

Hi,

I'm afraid the original issue has not been fixed by ce89fd9758.

I recompiled master with this commit and I am not seeing crashes with Laruence's code, but I am
still getting segfaults in zend_hash_index_find_bucket with the original repro script
(https://github.com/pavelkouril/php7-sigsegv). :(


Previous Comments:
------------------------------------------------------------------------
[2015-08-17 09:58:41] dmitry@php.net

Automatic comment on behalf of dmitry@zend.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ce89fd9758fffd6c4bffca130829734ac3fca8ec
Log: Fixed bug #70262 (Accessing array crashes PHP 7.0beta3)

------------------------------------------------------------------------
[2015-08-16 07:02:06] laruence@php.net

yes, they behavior different result(double free result undefined behavior), but they have the both
same root cause.. ;)

I need find out the root cause first, then can according to that made a simpler reproduce case..

------------------------------------------------------------------------
[2015-08-15 15:37:05] bugs dot php dot net at majkl578 dot cz

Hi laruence,

the original repro script (the php7-sigsegv repo) crashed with a regular sigsegv while your repro
script ends prematurely for me (7.0.0beta3 DEBUG without your patch) with the following assert:
php: Zend/zend_gc.c:226: void gc_possible_root(zend_refcounted *): Assertion
`((zend_refcounted*)(ref))->u.v.type == 7 || ((zend_refcounted*)(ref))->u.v.type == 8'
failed.

Anyway, your patch fixed both. :)

Thanks for your awesome work, these issues are always PITA...

------------------------------------------------------------------------
[2015-08-15 15:25:13] pavel dot kouril at hotmail dot com

I compiled PHP on Windows with your change and the application now works - thanks a lot!

------------------------------------------------------------------------
[2015-08-15 11:26:34] laruence@php.net

This was really a tough one to figure out the root cause :<

after all, I finally get the reason, and made a simple reproduce case:

<?php

class C {
    public $arguments;
    public function __construct($arg) {
        $this->arguments = $arg;
    }
}

function & a(&$arg) {
    $c = new C($arg);
    $arg[] = $c;
    return $c;
}

function c($arr) {
    a($arr)->arguments[0] = "bad";
}

$arr = array();
$arr[] = "foo";
$arr[] = "bar";
c($arr);
var_dump($arr);
?>

and a fix might be: https://gist.github.com/laruence/848e69d0a43846b61d26

all tests is passed....

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70262


--
Edit this bug report at https://bugs.php.net/bug.php?id=70262&edit=1


Thread (8 messages)

« previous php.bugs (#195257) next »