Bug #70398 [Asn->Csd]: SIGSEGV, Segmentation fault zend_ast_destroy_ex
| From: | laruence@php.net | Date: | Thu, 03 Sep 2015 05:07:50 +0000 |
| Subject: | Bug #70398 [Asn->Csd]: SIGSEGV, Segmentation fault zend_ast_destroy_ex | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195728@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70398&edit=1
ID: 70398
Updated by: laruence@php.net
Reported by: opitz dot alexander at googlemail dot com
Summary: SIGSEGV, Segmentation fault zend_ast_destroy_ex
-Status: Assigned
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: Linux
PHP Version: 7.0.0RC1
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=6815c08e2939f49a2ac9087924d58448edb401ba
Log: Fixed bug #70398 (SIGSEGV, Segmentation fault zend_ast_destroy_ex)
Previous Comments:
------------------------------------------------------------------------
[2015-09-02 16:58:27] bwoebi@php.net
hmm, forget that, in case of an array, it'll fail, because the arrays have the ZVAL_PTR_DTOR as
destructor... So, not sure yet, what's best.
------------------------------------------------------------------------
[2015-09-02 16:54:22] bwoebi@php.net
Hence, I propose this alternative patch (assuming constants are only ever freed at the end of the
run):
diff --git a/Zend/zend_constants.c b/Zend/zend_constants.c
index 8d1be74..10648e4 100644
--- a/Zend/zend_constants.c
+++ b/Zend/zend_constants.c
@@ -33,7 +33,9 @@ void free_zend_constant(zval *zv)
zend_constant *c = Z_PTR_P(zv);
if (!(c->flags & CONST_PERSISTENT)) {
- zval_dtor(&c->value);
+ if (Z_TYPE(c->value) != IS_RESOURCE) {
+ zval_dtor(&c->value);
+ }
} else {
zval_internal_dtor(&c->value);
}
------------------------------------------------------------------------
[2015-09-02 16:39:06] bwoebi@php.net
That fixes the issue, but is it safe? There might be places directly operating on the zend_resource
* and manipulating its refcount [under the assumption that all resources are refcounted].
Also, even if it should be safe, copy_constant_array() needs to be patched too.
------------------------------------------------------------------------
[2015-09-02 15:22:37] laruence@php.net
could you please verify whether the following patch fixed the problem?
diff --git a/Zend/zend_builtin_functions.c b/Zend/zend_builtin_functions.c
index fc834df..5dceaae 100644
--- a/Zend/zend_builtin_functions.c
+++ b/Zend/zend_builtin_functions.c
@@ -864,6 +864,10 @@ repeat:
}
ZVAL_DUP(&c.value, val);
+ if (Z_TYPE_INFO(c.value) == IS_RESOURCE_EX) {
+ /* disable resource constant destruction */
+ Z_TYPE_INFO(c.value) = IS_RESOURCE;
+ }
zval_ptr_dtor(&val_free);
register_constant:
c.flags = case_sensitive; /* non persistent */
------------------------------------------------------------------------
[2015-09-02 15:15:29] laruence@php.net
it can not work, since resource dtor may call some user function that uses constants
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70398
--
Edit this bug report at https://bugs.php.net/bug.php?id=70398&edit=1