Edit report at https://bugs.php.net/bug.php?id=70860&edit=1
ID: 70860
User updated by: a dot cobest at gmail dot com
Reported by: a dot cobest at gmail dot com
Summary: Broken pointer in the memory heap.
Status: Open
Type: Bug
Package: Scripting Engine problem
Operating System: any
PHP Version: 7.0.0RC6
Block user comment: N
Private report: N
New Comment:
Typo in test:
---------------
PHP_FUNCTION(double_free) {
char * tmp = emalloc(sizeof(char)*7);
memcpy(tmp, "alloc1", sizeof("alloc1"));
efree(tmp);
efree(tmp);
char * tmp1 = emalloc(sizeof(char)*4);
memcpy(tmp1, "all2", sizeof("all2"));
char * tmp2 = emalloc(sizeof(char)*4);
memcpy(tmp2, "all3", sizeof("all3")); // tmp1 has string "all3"
}
Previous Comments:
------------------------------------------------------------------------
[2015-11-05 12:07:02] a dot cobest at gmail dot com
typo
------------------------------------------------------------------------
[2015-11-05 12:06:06] a dot cobest at gmail dot com
Description:
------------
Short description: Broken pointer may appear due to the fact that there is no checking that the
memory has been "freed".
Long description: Rewriting the extension to php7 often get a Segmentation fault. it turned out that
if somewhere I release the memory I get SIGSEGV in an unexpected place.
The memory manager does not have a check that the memory has already been freed earlier (example
attached). This problem will produce strange and hard-to-diagnose bugs
Like this (also like this https://bugs.php.net/bug.php?id=70249 or this https://bugs.php.net/bug.php?id=70033 or this https://bugs.php.net/bug.php?id=70017 etc):
php -v:
PHP 7.0.0RC6 (cli) (built: Nov 2 2015 10:24:35) ( NTS DEBUG )
Copyright (c) 1997-2015 The PHP Group
Zend Engine v3.0.0-dev, Copyright (c) 1998-2015 Zend Technologies
uname -a:
Darwin shadow 14.5.0 Darwin Kernel Version 14.5.0: Wed Jul 29 02:26:53 PDT 2015;
root:xnu-2782.40.9~1/RELEASE_X86_64 x86_64
OS:
MacOS 10.10.5
gdb backtrace:
Program received signal SIGSEGV, Segmentation fault.
0x00000001003cd013 in zend_mm_alloc_small (heap=0x101200040, size=72, bin_num=8,
__zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:1291
1291 heap->free_slot[bin_num] = p->next_free_slot;
Thread 1 (Thread 0xf03 of process 97454):
#0 0x00000001003cd013 in zend_mm_alloc_small (heap=0x101200040, size=72, bin_num=8,
__zend_filename=0x10090b633 "Zend/zend_string.h", __zend_lineno=121,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at Zend/zend_alloc.c:1291
#1 0x00000001003ca38e in zend_mm_alloc_heap (heap=0x101200040, size=72, __zend_filename=0x10090b633
"Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0)
at Zend/zend_alloc.c:1358
#2 0x00000001003cb4bf in _emalloc (size=40, __zend_filename=0x10090b633
"Zend/zend_string.h", __zend_lineno=121, __zend_orig_filename=0x0, __zend_orig_lineno=0)
at Zend/zend_alloc.c:2442
#3 0x00000001004282ca in zend_string_alloc (len=8, persistent=0) at Zend/zend_string.h:121
#4 0x0000000100421b5f in zend_string_init (str=0x1008d2b73 "function", len=8,
persistent=0) at Zend/zend_string.h:157
#5 0x0000000100421c8f in _zend_hash_str_update (ht=0x102beb120, str=0x1008d2b73
"function", len=8, pData=0x7fff5fbfdd68, __zend_filename=0x10090ed84
"Zend/zend_hash.h", __zend_lineno=393) at Zend/zend_hash.c:598
#6 0x0000000100410db0 in zend_symtable_str_update (ht=0x102beb120, str=0x1008d2b73
"function", len=8, pData=0x7fff5fbfdd68) at Zend/zend_hash.h:393
#7 0x0000000100410ff3 in add_assoc_str_ex (arg=0x7fff5fbfdea0, key=0x1008d2b73
"function", key_len=8, str=0x102b748c0) at Zend/zend_API.c:1361
#8 0x000000010042a211 in zend_fetch_debug_backtrace (return_value=0x7fff5fbfdf58, skip_last=0,
options=0, limit=0) at Zend/zend_builtin_functions.c:2595
#9 0x0000000100442da6 in zend_default_exception_new_ex (class_type=0x103805db8, skip_top_traces=0)
at Zend/zend_exceptions.c:201
#10 0x0000000100441af7 in zend_default_exception_new (class_type=0x103805db8) at
Zend/zend_exceptions.c:224
#11 0x0000000100410c13 in _object_and_properties_init (arg=0x7fff5fbfe098, class_type=0x103805db8,
properties=0x0, __zend_filename=0x1009158a4 "Zend/zend_vm_execute.h", __zend_lineno=3356)
at Zend/zend_API.c:1288
#12 0x0000000100410c76 in _object_init_ex (arg=0x7fff5fbfe098, class_type=0x103805db8,
__zend_filename=0x1009158a4 "Zend/zend_vm_execute.h", __zend_lineno=3356) at
Zend/zend_API.c:1296
#13 0x000000010049dea1 in ZEND_NEW_SPEC_CONST_HANDLER (execute_data=0x10121c350) at
Zend/zend_vm_execute.h:3356
#14 0x00000001004712f4 in execute_ex (ex=0x10121bd00) at Zend/zend_vm_execute.h:417
#15 0x00000001003ed59e in zend_call_function (fci=0x7fff5fbfe3d0, fci_cache=0x7fff5fbfe3a8) at
Zend/zend_execute_API.c:854
#16 0x0000000100165bcb in zim_reflection_method_invokeArgs (execute_data=0x10121bc80,
return_value=0x10121b950) at ext/reflection/php_reflection.c:3370
#17 0x000000010049c267 in ZEND_DO_FCALL_SPEC_HANDLER (execute_data=0x10121b750) at
Zend/zend_vm_execute.h:842
#18 0x00000001004712f4 in execute_ex (ex=0x101217030) at Zend/zend_vm_execute.h:417
#19 0x0000000100471460 in zend_execute (op_array=0x101273300, return_value=0x0) at
Zend/zend_vm_execute.h:458
#20 0x000000010040b583 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
Zend/zend.c:1428
#21 0x000000010035abc6 in php_execute_script (primary_file=0x7fff5fbff308) at main/main.c:2471
#22 0x00000001005047b3 in do_cli (argc=6, argv=0x7fff5fbffa28) at sapi/cli/php_cli.c:974
#23 0x00000001005035de in main (argc=6, argv=0x7fff5fbffa28) at sapi/cli/php_cli.c:1345
Test script:
---------------
PHP_FUNCTION(double_free) {
char * tmp = emalloc(sizeof(char)*7);
memcpy(tmp, "alloc1", sizeof("alloc1")+1);
efree(tmp);
efree(tmp);
char * tmp1 = emalloc(sizeof(char)*4);
memcpy(tmp1, "all2", sizeof("all2")+1);
char * tmp2 = emalloc(sizeof(char)*4);
memcpy(tmp2, "all3", sizeof("all3")+1); // tmp1 has string "all3"
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70860&edit=1