Bug #72257 [Opn]: "get_defined_constants(true)" core dump

From: Date: Mon, 30 May 2016 03:03:02 +0000
Subject: Bug #72257 [Opn]: "get_defined_constants(true)" core dump
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201329@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72257&edit=1

 ID:                 72257
 User updated by:    jccgls001 at 126 dot com
 Reported by:        jccgls001 at 126 dot com
 Summary:            "get_defined_constants(true)" core dump
 Status:             Open
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   linux 2.6
 PHP Version:        7.0.6
 Block user comment: N
 Private report:     N

 New Comment:

thanks for you apply~ this problem really troubles me a lot ...

I use this command:
USE_ZEND_ALLOC valgrind -r -n "var_dump(get_defined_constants(true));"

valgrind show these infos:
==25809== Memcheck, a memory error detector
==25809== Copyright (C) 2002-2012, and GNU GPL'd, by Julian Seward et al.
==25809== Using Valgrind-3.8.1 and LibVEX; rerun with -h for copyright info
==25809== Command: install/php/bin/php -n -r var_dump(get_defined_constants(true));
==25809== 
==25809== Use of uninitialised value of size 8
==25809==    at 0x49095B2: strlen (mc_replace_strmem.c:399)
==25809==    by 0xA652B5: zif_get_defined_constants (zend_builtin_functions.c:2227)
==25809==    by 0xAB1780: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==25809==    by 0xAB04BB: execute_ex (zend_vm_execute.h:417)
==25809==    by 0xAB0C65: zend_execute (zend_vm_execute.h:458)
==25809==    by 0xA18F77: zend_eval_stringl (zend_execute_API.c:1135)
==25809==    by 0xA19134: zend_eval_stringl_ex (zend_execute_API.c:1176)
==25809==    by 0xA191AC: zend_eval_string_ex (zend_execute_API.c:1187)
==25809==    by 0xB6A05B: do_cli (php_cli.c:1005)
==25809==    by 0xB6B0F4: main (php_cli.c:1344)
==25809== 
==25809== Invalid read of size 1
==25809==    at 0x49095B2: strlen (mc_replace_strmem.c:399)
==25809==    by 0xA652B5: zif_get_defined_constants (zend_builtin_functions.c:2227)
==25809==    by 0xAB1780: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==25809==    by 0xAB04BB: execute_ex (zend_vm_execute.h:417)
==25809==    by 0xAB0C65: zend_execute (zend_vm_execute.h:458)
==25809==    by 0xA18F77: zend_eval_stringl (zend_execute_API.c:1135)
==25809==    by 0xA19134: zend_eval_stringl_ex (zend_execute_API.c:1176)
==25809==    by 0xA191AC: zend_eval_string_ex (zend_execute_API.c:1187)
==25809==    by 0xB6A05B: do_cli (php_cli.c:1005)
==25809==    by 0xB6B0F4: main (php_cli.c:1344)
==25809==  Address 0x0 is not stack'd, malloc'd or (recently) free'd
==25809== 
==25809== 
==25809== Process terminating with default action of signal 11 (SIGSEGV)
==25809==  Access not within mapped region at address 0x0
==25809==    at 0x49095B2: strlen (mc_replace_strmem.c:399)
==25809==    by 0xA652B5: zif_get_defined_constants (zend_builtin_functions.c:2227)
==25809==    by 0xAB1780: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==25809==    by 0xAB04BB: execute_ex (zend_vm_execute.h:417)
==25809==    by 0xAB0C65: zend_execute (zend_vm_execute.h:458)
==25809==    by 0xA18F77: zend_eval_stringl (zend_execute_API.c:1135)
==25809==    by 0xA19134: zend_eval_stringl_ex (zend_execute_API.c:1176)
==25809==    by 0xA191AC: zend_eval_string_ex (zend_execute_API.c:1187)
==25809==    by 0xB6A05B: do_cli (php_cli.c:1005)
==25809==    by 0xB6B0F4: main (php_cli.c:1344)
==25809==  If you believe this happened as a result of a stack
==25809==  overflow in your program's main thread (unlikely but
==25809==  possible), you can try to increase the size of the
==25809==  main thread stack using the --main-stacksize= flag.
==25809==  The main thread stack size used in this run was 10485760.
==25809== 
==25809== HEAP SUMMARY:
==25809==     in use at exit: 2,092,430 bytes in 16,256 blocks
==25809==   total heap usage: 19,987 allocs, 3,731 frees, 2,593,732 bytes allocated
==25809== 
==25809== LEAK SUMMARY:
==25809==    definitely lost: 923 bytes in 13 blocks
==25809==    indirectly lost: 0 bytes in 0 blocks
==25809==      possibly lost: 1,213,506 bytes in 12,245 blocks
==25809==    still reachable: 878,001 bytes in 3,998 blocks
==25809==         suppressed: 0 bytes in 0 blocks
==25809== Rerun with --leak-check=full to see details of leaked memory
==25809== 
==25809== For counts of detected and suppressed errors, rerun with: -v
==25809== Use --track-origins=yes to see where uninitialised values come from
==25809== ERROR SUMMARY: 2 errors from 2 contexts (suppressed: 7 from 7)

it seems like strlen() used a uninitialised char*(size of 8)

i think this problem maybe caused by:
module_names in zend_builtin_functions.c(2203), it should assign "Core" to
module_names[1], but actually assign to module_names[0], which will lead to error when call
"strlen(module_names[1])" in line 2227.


----------------------
by the way, "php -m" show:
[PHP Modules]
bcmath
Core
ctype
curl
date
dom
fileinfo
filter
gd
hash
iconv
json
libxml
mbstring
mcrypt
openssl
pcntl
pcre
PDO
pdo_mysql
pdo_sqlite
Phar
posix
Reflection
session
shmop
SimpleXML
soap
sockets
SPL
sqlite3
standard
sysvsem
tokenizer
xml
xmlreader
xmlrpc
xmlwriter
zip
zlib

[Zend Modules]


Previous Comments:
------------------------------------------------------------------------
[2016-05-29 12:12:44] bwoebi@php.net

The only way this code could crash is if module->name is invalid.

Try:
USE_ZEND_ALLOC=0 valgrind php -n -r "var_dump(get_define_constants(true));"

Perhaps this finds something, but locally I cannot reproduce it either.

Also, what does php -m tell you?

------------------------------------------------------------------------
[2016-05-23 12:39:02] jccgls001 at 126 dot com

Following your advise, I use php -n -r "var_dump(get_define_constants(true);" command but
segmentation fault again. the backtrace info is same as before.

I have removed all third-party extensions when build source and before run code.

------------------------------------------------------------------------
[2016-05-23 12:13:26] laruence@php.net

try again after you disable any third-part extension.

like: php -n -r "var_dump(get_define_constants(true);", then add them one by one to check
which extension cause this.

------------------------------------------------------------------------
[2016-05-23 12:02:20] jccgls001 at 126 dot com

backtrace is here :
------------------------

Using host libthread_db library "/lib64/tls/libthread_db.so.1".
Core was generated by `install/php/bin/php -r get_defined_constants(true);'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x000000302af6ff40 in strlen ()
   from /home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/install/php/bin/../../lib/gcc-3.4.5/libc.so.6
(gdb) bt
#0  0x000000302af6ff40 in strlen ()
   from /home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/install/php/bin/../../lib/gcc-3.4.5/libc.so.6
#1  0x0000000000a652b6 in zif_get_defined_constants (execute_data=0x7f9e74c120a0,
return_value=0x7f9e74c12090)
    at
/home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/build/php-7.0.6/Zend/zend_builtin_functions.c:2227
#2  0x0000000000ab1781 in ZEND_DO_ICALL_SPEC_HANDLER (execute_data=0x7f9e74c12030)
    at /home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/build/php-7.0.6/Zend/zend_vm_execute.h:586
#3  0x0000000000ab04bc in execute_ex (ex=0x7f9e74c12030)
    at /home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/build/php-7.0.6/Zend/zend_vm_execute.h:417
#4  0x0000000000ab0c66 in zend_execute (op_array=0x7f9e74c610e0, return_value=0x7ffffa23d620)
    at /home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/build/php-7.0.6/Zend/zend_vm_execute.h:458
#5  0x0000000000a18f78 in zend_eval_stringl (str=0x17d4cd0 "get_defined_constants(true);",
str_len=28, retval_ptr=0x0, 
    string_name=0x1353fcc "Command line code")
    at /home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/build/php-7.0.6/Zend/zend_execute_API.c:1135
#6  0x0000000000a19135 in zend_eval_stringl_ex (str=0x17d4cd0
"get_defined_constants(true);", str_len=28, retval_ptr=0x0, 
    string_name=0x1353fcc "Command line code", handle_exceptions=1)
    at /home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/build/php-7.0.6/Zend/zend_execute_API.c:1176
#7  0x0000000000a191ad in zend_eval_string_ex (str=0x17d4cd0
"get_defined_constants(true);", retval_ptr=0x0, 
    string_name=0x1353fcc "Command line code", handle_exceptions=1)
    at /home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/build/php-7.0.6/Zend/zend_execute_API.c:1187
#8  0x0000000000b6a05c in do_cli (argc=3, argv=0x17d4c60)
    at /home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/build/php-7.0.6/sapi/cli/php_cli.c:1005
#9  0x0000000000b6b0f5 in main (argc=3, argv=0x17d4c60)
    at /home/users/lvshun_iwm/php7_odp/trunk/php/.tmp/build/php-7.0.6/sapi/cli/php_cli.c:1344

------------------------------------------------------------------------
[2016-05-23 10:23:55] laruence@php.net

Thank you for this bug report. To properly diagnose the problem, we
need a backtrace to see what is happening behind the scenes. To
find out how to generate a backtrace, please read
http://bugs.php.net/bugs-generating-backtrace.php
for *NIX and
http://bugs.php.net/bugs-generating-backtrace-win32.php
for Win32

Once you have generated a backtrace, please submit it to this bug
report and change the status back to "Open". Thank you for helping
us make PHP better.

I can not reproduce this.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=72257


--
Edit this bug report at https://bugs.php.net/bug.php?id=72257&edit=1


Thread (16 messages)

« previous php.bugs (#201329) next »