Bug #70398 [Asn]: SIGSEGV, Segmentation fault zend_ast_destroy_ex
| From: | bwoebi@php.net | Date: | Wed, 02 Sep 2015 16:54:23 +0000 |
| Subject: | Bug #70398 [Asn]: SIGSEGV, Segmentation fault zend_ast_destroy_ex | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195714@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70398&edit=1
ID: 70398
Updated by: bwoebi@php.net
Reported by: opitz dot alexander at googlemail dot com
Summary: SIGSEGV, Segmentation fault zend_ast_destroy_ex
Status: Assigned
Type: Bug
Package: *General Issues
Operating System: Linux
PHP Version: 7.0.0RC1
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Hence, I propose this alternative patch (assuming constants are only ever freed at the end of the
run):
diff --git a/Zend/zend_constants.c b/Zend/zend_constants.c
index 8d1be74..10648e4 100644
--- a/Zend/zend_constants.c
+++ b/Zend/zend_constants.c
@@ -33,7 +33,9 @@ void free_zend_constant(zval *zv)
zend_constant *c = Z_PTR_P(zv);
if (!(c->flags & CONST_PERSISTENT)) {
- zval_dtor(&c->value);
+ if (Z_TYPE(c->value) != IS_RESOURCE) {
+ zval_dtor(&c->value);
+ }
} else {
zval_internal_dtor(&c->value);
}
Previous Comments:
------------------------------------------------------------------------
[2015-09-02 16:39:06] bwoebi@php.net
That fixes the issue, but is it safe? There might be places directly operating on the zend_resource
* and manipulating its refcount [under the assumption that all resources are refcounted].
Also, even if it should be safe, copy_constant_array() needs to be patched too.
------------------------------------------------------------------------
[2015-09-02 15:22:37] laruence@php.net
could you please verify whether the following patch fixed the problem?
diff --git a/Zend/zend_builtin_functions.c b/Zend/zend_builtin_functions.c
index fc834df..5dceaae 100644
--- a/Zend/zend_builtin_functions.c
+++ b/Zend/zend_builtin_functions.c
@@ -864,6 +864,10 @@ repeat:
}
ZVAL_DUP(&c.value, val);
+ if (Z_TYPE_INFO(c.value) == IS_RESOURCE_EX) {
+ /* disable resource constant destruction */
+ Z_TYPE_INFO(c.value) = IS_RESOURCE;
+ }
zval_ptr_dtor(&val_free);
register_constant:
c.flags = case_sensitive; /* non persistent */
------------------------------------------------------------------------
[2015-09-02 15:15:29] laruence@php.net
it can not work, since resource dtor may call some user function that uses constants
------------------------------------------------------------------------
[2015-09-02 12:48:19] bwoebi@php.net
Related To: Bug #70399
------------------------------------------------------------------------
[2015-09-02 12:33:21] bwoebi@php.net
./sapi/cli/php -r 'define("TEST", fopen("php://temp",
"w+b"));'
gives me a few invalid reads with valgrind.
The fix is actually simple: In shutdown_executor(), move the call to
clean_non_persistent_constants(); a few lines up above zend_close_rsrc_list(&EG(regular_list));
Though, I'm not sure if that might have side-effects [AFAIK, misordering in shutdown often
causes subtle breaks] ⦠so, can you please verify, Xinchen?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70398
--
Edit this bug report at https://bugs.php.net/bug.php?id=70398&edit=1