Bug #72854 [Csd]: PHP Crashes on duplicate destructor call
| From: | nikic@php.net | Date: | Tue, 16 Aug 2016 19:14:05 +0000 |
| Subject: | Bug #72854 [Csd]: PHP Crashes on duplicate destructor call | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203328@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72854&edit=1
ID: 72854
Updated by: nikic@php.net
Reported by: php at abiusx dot com
Summary: PHP Crashes on duplicate destructor call
Status: Closed
Type: Bug
Package: Class/Object related
Operating System: Mac OS X, Linux
PHP Version: 7.0.9
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Yes, the example does not segfault, but the use-after-free is visible in valgrind (and a leak
message in debug builds).
This resolves the segfault for me, but it may well be that you are seeing additional/different
issues. For example, I do not get a segfault on 5.6, while you mention that the problem exists on
PHP 5 as well.
Previous Comments:
------------------------------------------------------------------------
[2016-08-16 19:08:07] nikic@php.net
Automatic comment on behalf of nikic
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e2230c17d3e17981c739cb858bc78d47d2365836
Log: Fix bug #72854
------------------------------------------------------------------------
[2016-08-16 19:07:00] nikic@php.net
Automatic comment on behalf of nikic
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e2230c17d3e17981c739cb858bc78d47d2365836
Log: Fix bug #72854
------------------------------------------------------------------------
[2016-08-16 18:37:16] php at abiusx dot com
Your sample code is not segfaulting for me. Plus, it has a NOTICE.
------------------------------------------------------------------------
[2016-08-16 18:35:53] php at abiusx dot com
It sounds reasonable. All segfaults might be due to the same bug. To cause the other segfaults,
please comment out wpdb destruct method entirely and rerun, but I highly suspect they are all of the
same type. I faced a few and they behaved very similarly.
------------------------------------------------------------------------
[2016-08-16 18:09:22] nikic@php.net
Reproduce script for at least one issue:
<?php
function get() {
$t = new stdClass;
$t->prop = $t;
return $t;
}
$i = 42;
get($t)->prop =& $i;
The problem here is that get($t)->prop =& $i destroys the stdClass object, but that is also
the object to which the assignment happens, so we end up writing a destroyed object.
This can be avoided by using an intermediate garbage zval in assign_to_reference. Doing so also
fixes the segfault (I only see the one, with and without --diehard) on your test case.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72854
--
Edit this bug report at https://bugs.php.net/bug.php?id=72854&edit=1