Bug #70690 [NEW]: do_bind_inherited_class error printing code can causes segfaults
| From: | tandre at ifwe dot co | Date: | Sun, 11 Oct 2015 06:16:32 +0000 |
| Subject: | Bug #70690 [NEW]: do_bind_inherited_class error printing code can causes segfaults | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-196523@lists.php.net to get a copy of this message | ||
From: tandre at ifwe dot co
Operating system: All
PHP version: 7.0Git-2015-10-11 (Git)
Package: opcache
Bug Type: Bug
Bug description:do_bind_inherited_class error printing code can causes segfaults
Description:
------------
See this line of code in do_bind_inherited_class (zend_compile.c, line
1038)
That code attempted to treat the same zval for op2 both as an object and
a
string on the same line to print an error message(op2 is actually a
string)
Existing code:
zend_error_noreturn(E_COMPILE_ERROR, "Cannot declare %s %s, because the
name is already in use", zend_get_object_type(Z_OBJCE_P(op2)),
Z_STRVAL_P(op2));
Suggested fix:
zend_error_noreturn(E_COMPILE_ERROR, "Cannot declare %s %s, because the
name is already in use", "trait/interface/class", Z_STRVAL_P(op2));
Because the absense of a class entry triggers this the error,
the best thing that could be done
would probably be to print an unknown type instead of the object type.
The severity is minor. Filing this under Opcache since opcache is the
only extension I saw using this
function. I haven't been able to make Opcache reach this line of code,
but it could theoretically happen.
Test script:
---------------
// Call C function zend_do_delayed_early_binding on an op_array without
creating a class entry for the subclass being bound (for optype
ZEND_DECLARE_INHERITED_CLASS))
// In theory, opcache corruption or bugs in other accelerators could
trigger this error.
Expected result:
----------------
zend_error_noreturn prints a compile error message when the class entry
doesn't exist, doesn't segfault.
Actual result:
--------------
Segfaults while attempting to print an error message
--
Edit bug report at https://bugs.php.net/bug.php?id=70690&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70690&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70690&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70690&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=70690&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=70690&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=70690&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=70690&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=70690&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=70690&r=support
Expected behavior: https://bugs.php.net/fix.php?id=70690&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=70690&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=70690&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=70690&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70690&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=70690&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=70690&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=70690&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=70690&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=70690&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=70690&r=mysqlcfg