Bug #70860 [NEW]: Broken pointer in the heap memory.
| From: | a dot cobest at gmail dot com | Date: | Thu, 05 Nov 2015 12:06:11 +0000 |
| Subject: | Bug #70860 [NEW]: Broken pointer in the heap memory. | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-197041@lists.php.net to get a copy of this message | ||
From: a dot cobest at gmail dot com
Operating system: any
PHP version: 7.0.0RC6
Package: Scripting Engine problem
Bug Type: Bug
Bug description:Broken pointer in the heap memory.
Description:
------------
Short description: Broken pointer may appear due to the fact that there
is no checking that the memory has been "freed".
Long description: Rewriting the extension to php7 often get a
Segmentation fault. it turned out that if somewhere I release the memory
I get SIGSEGV in an unexpected place.
The memory manager does not have a check that the memory has already
been freed earlier (example attached). This problem will produce strange
and hard-to-diagnose bugs
Like this (also like this https://bugs.php.net/bug.php?id=70249 or this
https://bugs.php.net/bug.php?id=70033 or this
https://bugs.php.net/bug.php?id=70017 etc):
php -v:
PHP 7.0.0RC6 (cli) (built: Nov 2 2015 10:24:35) ( NTS DEBUG )
Copyright (c) 1997-2015 The PHP Group
Zend Engine v3.0.0-dev, Copyright (c) 1998-2015 Zend Technologies
uname -a:
Darwin shadow 14.5.0 Darwin Kernel Version 14.5.0: Wed Jul 29 02:26:53
PDT 2015; root:xnu-2782.40.9~1/RELEASE_X86_64 x86_64
OS:
MacOS 10.10.5
gdb backtrace:
Program received signal SIGSEGV, Segmentation fault.
0x00000001003cd013 in zend_mm_alloc_small (heap=0x101200040, size=72,
bin_num=8, __zend_filename=0x10090b633 "Zend/zend_string.h",
__zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0) at
Zend/zend_alloc.c:1291
1291 heap->free_slot[bin_num] = p->next_free_slot;
Thread 1 (Thread 0xf03 of process 97454):
#0 0x00000001003cd013 in zend_mm_alloc_small (heap=0x101200040,
size=72, bin_num=8, __zend_filename=0x10090b633 "Zend/zend_string.h",
__zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0) at
Zend/zend_alloc.c:1291
#1 0x00000001003ca38e in zend_mm_alloc_heap (heap=0x101200040, size=72,
__zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at
Zend/zend_alloc.c:1358
#2 0x00000001003cb4bf in _emalloc (size=40, __zend_filename=0x10090b633
"Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0,
__zend_orig_lineno=0) at Zend/zend_alloc.c:2442
#3 0x00000001004282ca in zend_string_alloc (len=8, persistent=0) at
Zend/zend_string.h:121
#4 0x0000000100421b5f in zend_string_init (str=0x1008d2b73 "function",
len=8, persistent=0) at Zend/zend_string.h:157
#5 0x0000000100421c8f in _zend_hash_str_update (ht=0x102beb120,
str=0x1008d2b73 "function", len=8, pData=0x7fff5fbfdd68,
__zend_filename=0x10090ed84 "Zend/zend_hash.h", __zend_lineno=393) at
Zend/zend_hash.c:598
#6 0x0000000100410db0 in zend_symtable_str_update (ht=0x102beb120,
str=0x1008d2b73 "function", len=8, pData=0x7fff5fbfdd68) at
Zend/zend_hash.h:393
#7 0x0000000100410ff3 in add_assoc_str_ex (arg=0x7fff5fbfdea0,
key=0x1008d2b73 "function", key_len=8, str=0x102b748c0) at
Zend/zend_API.c:1361
#8 0x000000010042a211 in zend_fetch_debug_backtrace
(return_value=0x7fff5fbfdf58, skip_last=0, options=0, limit=0) at
Zend/zend_builtin_functions.c:2595
#9 0x0000000100442da6 in zend_default_exception_new_ex
(class_type=0x103805db8, skip_top_traces=0) at
Zend/zend_exceptions.c:201
#10 0x0000000100441af7 in zend_default_exception_new
(class_type=0x103805db8) at Zend/zend_exceptions.c:224
#11 0x0000000100410c13 in _object_and_properties_init
(arg=0x7fff5fbfe098, class_type=0x103805db8, properties=0x0,
__zend_filename=0x1009158a4 "Zend/zend_vm_execute.h",
__zend_lineno=3356) at Zend/zend_API.c:1288
#12 0x0000000100410c76 in _object_init_ex (arg=0x7fff5fbfe098,
class_type=0x103805db8, __zend_filename=0x1009158a4
"Zend/zend_vm_execute.h", __zend_lineno=3356) at Zend/zend_API.c:1296
#13 0x000000010049dea1 in ZEND_NEW_SPEC_CONST_HANDLER
(execute_data=0x10121c350) at Zend/zend_vm_execute.h:3356
#14 0x00000001004712f4 in execute_ex (ex=0x10121bd00) at
Zend/zend_vm_execute.h:417
#15 0x00000001003ed59e in zend_call_function (fci=0x7fff5fbfe3d0,
fci_cache=0x7fff5fbfe3a8) at Zend/zend_execute_API.c:854
#16 0x0000000100165bcb in zim_reflection_method_invokeArgs
(execute_data=0x10121bc80, return_value=0x10121b950) at
ext/reflection/php_reflection.c:3370
#17 0x000000010049c267 in ZEND_DO_FCALL_SPEC_HANDLER
(execute_data=0x10121b750) at Zend/zend_vm_execute.h:842
#18 0x00000001004712f4 in execute_ex (ex=0x101217030) at
Zend/zend_vm_execute.h:417
#19 0x0000000100471460 in zend_execute (op_array=0x101273300,
return_value=0x0) at Zend/zend_vm_execute.h:458
#20 0x000000010040b583 in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at Zend/zend.c:1428
#21 0x000000010035abc6 in php_execute_script
(primary_file=0x7fff5fbff308) at main/main.c:2471
#22 0x00000001005047b3 in do_cli (argc=6, argv=0x7fff5fbffa28) at
sapi/cli/php_cli.c:974
#23 0x00000001005035de in main (argc=6, argv=0x7fff5fbffa28) at
sapi/cli/php_cli.c:1345
Test script:
---------------
PHP_FUNCTION(double_free) {
char * tmp = emalloc(sizeof(char)*7);
memcpy(tmp, "alloc1", sizeof("alloc1")+1);
efree(tmp);
efree(tmp);
char * tmp1 = emalloc(sizeof(char)*4);
memcpy(tmp1, "all2", sizeof("all2")+1);
char * tmp2 = emalloc(sizeof(char)*4);
memcpy(tmp2, "all3", sizeof("all3")+1); // tmp1 has string "all3"
}
--
Edit bug report at https://bugs.php.net/bug.php?id=70860&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70860&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70860&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70860&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=70860&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=70860&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=70860&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=70860&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=70860&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=70860&r=support
Expected behavior: https://bugs.php.net/fix.php?id=70860&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=70860&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=70860&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=70860&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70860&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=70860&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=70860&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=70860&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=70860&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=70860&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=70860&r=mysqlcfg