Bug #70863 [Csd]: Incorect logic to increment_function for proxy objects
Edit report at https://bugs.php.net/bug.php?id=70863&edit=1
ID: 70863
Updated by: ab@php.net
Reported by: jsoumelidis at gmail dot com
Summary: Incorect logic to increment_function for proxy
objects
Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Windows
PHP Version: 7.0.0RC6
-Assigned To:
+Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Yeah, the decrement function was already done, thanks for the other catch, done in
a3f1154b3d95aa9508cef19102ad553fed4f9189.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2015-11-09 18:12:05] ab@php.net
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=68910e314ff62bd9f326cc11a48bfd65e5a32220
Log: Fixed bug #70863 Incorect logic to increment_function for proxy objects
------------------------------------------------------------------------
[2015-11-07 13:29:27] jsoumelidis at gmail dot com
Same fix should be applied to functions "ZEND_TRY_BINARY_OP1_OBJECT_OPERATION"
(zend_operators.h:760) and "decrement_function" (zend_operators.c:2348)
------------------------------------------------------------------------
[2015-11-06 22:11:31] ab@php.net
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=8155ecba61a9c724c7b2bdeb673602ae27923d71
Log: Fixed bug #70863 Incorect logic to increment_function for proxy objects
------------------------------------------------------------------------
[2015-11-05 19:35:16] jsoumelidis at gmail dot com
Description:
------------
Assume you have a (custom) proxy object that one wants to increment it's value ($obj++).
If get/set object handlers are defined for this object, the "increment_function" requests
a zval* from the get handler in order to icrement it's value and assign it back to the proxy
object through the set handler.
The problem is that the increment_function executes a Z_ADDREF_P on the returned zval* from the get
handler which crashes the proccess in case the returned pointer is not a refcounted zval.
File: zend_operators.c Line: 2280
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70863&edit=1
Thread (4 messages)