Bug #70690 [NEW]: do_bind_inherited_class error printing code can causes segfaults

From: Date: Sun, 11 Oct 2015 06:16:32 +0000
Subject: Bug #70690 [NEW]: do_bind_inherited_class error printing code can causes segfaults
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196523@lists.php.net to get a copy of this message
From: tandre at ifwe dot co Operating system: All PHP version: 7.0Git-2015-10-11 (Git) Package: opcache Bug Type: Bug Bug description:do_bind_inherited_class error printing code can causes segfaults Description: ------------ See this line of code in do_bind_inherited_class (zend_compile.c, line 1038) That code attempted to treat the same zval for op2 both as an object and a string on the same line to print an error message(op2 is actually a string) Existing code: zend_error_noreturn(E_COMPILE_ERROR, "Cannot declare %s %s, because the name is already in use", zend_get_object_type(Z_OBJCE_P(op2)), Z_STRVAL_P(op2)); Suggested fix: zend_error_noreturn(E_COMPILE_ERROR, "Cannot declare %s %s, because the name is already in use", "trait/interface/class", Z_STRVAL_P(op2)); Because the absense of a class entry triggers this the error, the best thing that could be done would probably be to print an unknown type instead of the object type. The severity is minor. Filing this under Opcache since opcache is the only extension I saw using this function. I haven't been able to make Opcache reach this line of code, but it could theoretically happen. Test script: --------------- // Call C function zend_do_delayed_early_binding on an op_array without creating a class entry for the subclass being bound (for optype ZEND_DECLARE_INHERITED_CLASS)) // In theory, opcache corruption or bugs in other accelerators could trigger this error. Expected result: ---------------- zend_error_noreturn prints a compile error message when the class entry doesn't exist, doesn't segfault. Actual result: -------------- Segfaults while attempting to print an error message -- Edit bug report at https://bugs.php.net/bug.php?id=70690&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70690&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70690&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70690&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=70690&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=70690&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=70690&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=70690&r=needscript Try newer version: https://bugs.php.net/fix.php?id=70690&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=70690&r=support Expected behavior: https://bugs.php.net/fix.php?id=70690&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=70690&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=70690&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=70690&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70690&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=70690&r=dst IIS Stability: https://bugs.php.net/fix.php?id=70690&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=70690&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=70690&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=70690&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=70690&r=mysqlcfg

« previous php.bugs (#196523) next »