Bug #70690 [Fbk->NoF]: do_bind_inherited_class error printing code can causes segfaults

From: Date: Sun, 25 Oct 2015 04:22:30 +0000
Subject: Bug #70690 [Fbk->NoF]: do_bind_inherited_class error printing code can causes segfaults
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196790@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70690&edit=1 ID: 70690 Updated by: php-bugs@lists.php.net Reported by: tandre at ifwe dot co Summary: do_bind_inherited_class error printing code can causes segfaults -Status: Feedback +Status: No Feedback Type: Bug Package: Scripting Engine problem Operating System: All PHP Version: 7.0Git-2015-10-11 (Git) Private report: N New Comment: No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. Previous Comments: ------------------------------------------------------------------------ [2015-10-11 13:49:35] felipe@php.net Which php code are you using to reproduce such segfault? ------------------------------------------------------------------------ [2015-10-11 06:16:28] tandre at ifwe dot co Description: ------------ See this line of code in do_bind_inherited_class (zend_compile.c, line 1038) That code attempted to treat the same zval for op2 both as an object and a string on the same line to print an error message(op2 is actually a string) Existing code: zend_error_noreturn(E_COMPILE_ERROR, "Cannot declare %s %s, because the name is already in use", zend_get_object_type(Z_OBJCE_P(op2)), Z_STRVAL_P(op2)); Suggested fix: zend_error_noreturn(E_COMPILE_ERROR, "Cannot declare %s %s, because the name is already in use", "trait/interface/class", Z_STRVAL_P(op2)); Because the absense of a class entry triggers this the error, the best thing that could be done would probably be to print an unknown type instead of the object type. The severity is minor. Filing this under Opcache since opcache is the only extension I saw using this function. I haven't been able to make Opcache reach this line of code, but it could theoretically happen. Test script: --------------- // Call C function zend_do_delayed_early_binding on an op_array without creating a class entry for the subclass being bound (for optype ZEND_DECLARE_INHERITED_CLASS)) // In theory, opcache corruption or bugs in other accelerators could trigger this error. Expected result: ---------------- zend_error_noreturn prints a compile error message when the class entry doesn't exist, doesn't segfault. Actual result: -------------- Segfaults while attempting to print an error message ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70690&edit=1

« previous php.bugs (#196790) next »