Bug #70863 [Csd]: Incorect logic to increment_function for proxy objects

From: Date: Mon, 09 Nov 2015 23:45:00 +0000
Subject: Bug #70863 [Csd]: Incorect logic to increment_function for proxy objects
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197142@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70863&edit=1

 ID:                 70863
 Updated by:         ab@php.net
 Reported by:        jsoumelidis at gmail dot com
 Summary:            Incorect logic to increment_function for proxy
                     objects
 Status:             Closed
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Windows
 PHP Version:        7.0.0RC6
-Assigned To:        
+Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

Yeah, the decrement function was already done, thanks for the other catch, done in
a3f1154b3d95aa9508cef19102ad553fed4f9189.

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2015-11-09 18:12:05] ab@php.net

Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=68910e314ff62bd9f326cc11a48bfd65e5a32220
Log: Fixed bug #70863 Incorect logic to increment_function for proxy objects

------------------------------------------------------------------------
[2015-11-07 13:29:27] jsoumelidis at gmail dot com

Same fix should be applied to functions "ZEND_TRY_BINARY_OP1_OBJECT_OPERATION"
(zend_operators.h:760) and "decrement_function" (zend_operators.c:2348)

------------------------------------------------------------------------
[2015-11-06 22:11:31] ab@php.net

Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=8155ecba61a9c724c7b2bdeb673602ae27923d71
Log: Fixed bug #70863 Incorect logic to increment_function for proxy objects

------------------------------------------------------------------------
[2015-11-05 19:35:16] jsoumelidis at gmail dot com

Description:
------------
Assume you have a (custom) proxy object that one wants to increment it's value ($obj++).
If get/set object handlers are defined for this object, the "increment_function" requests
a zval* from the get handler in order to icrement it's value and assign it back to the proxy
object through the set handler.
The problem is that the increment_function executes a Z_ADDREF_P on the returned zval* from the get
handler which crashes the proccess in case the returned pointer  is not a refcounted zval.
File: zend_operators.c Line: 2280



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70863&edit=1


Thread (4 messages)

« previous php.bugs (#197142) next »