Bug #72854 [Csd]: PHP Crashes on duplicate destructor call

From: Date: Tue, 16 Aug 2016 19:14:05 +0000
Subject: Bug #72854 [Csd]: PHP Crashes on duplicate destructor call
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203328@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72854&edit=1 ID: 72854 Updated by: nikic@php.net Reported by: php at abiusx dot com Summary: PHP Crashes on duplicate destructor call Status: Closed Type: Bug Package: Class/Object related Operating System: Mac OS X, Linux PHP Version: 7.0.9 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: Yes, the example does not segfault, but the use-after-free is visible in valgrind (and a leak message in debug builds). This resolves the segfault for me, but it may well be that you are seeing additional/different issues. For example, I do not get a segfault on 5.6, while you mention that the problem exists on PHP 5 as well. Previous Comments: ------------------------------------------------------------------------ [2016-08-16 19:08:07] nikic@php.net Automatic comment on behalf of nikic Revision: http://git.php.net/?p=php-src.git;a=commit;h=e2230c17d3e17981c739cb858bc78d47d2365836 Log: Fix bug #72854 ------------------------------------------------------------------------ [2016-08-16 19:07:00] nikic@php.net Automatic comment on behalf of nikic Revision: http://git.php.net/?p=php-src.git;a=commit;h=e2230c17d3e17981c739cb858bc78d47d2365836 Log: Fix bug #72854 ------------------------------------------------------------------------ [2016-08-16 18:37:16] php at abiusx dot com Your sample code is not segfaulting for me. Plus, it has a NOTICE. ------------------------------------------------------------------------ [2016-08-16 18:35:53] php at abiusx dot com It sounds reasonable. All segfaults might be due to the same bug. To cause the other segfaults, please comment out wpdb destruct method entirely and rerun, but I highly suspect they are all of the same type. I faced a few and they behaved very similarly. ------------------------------------------------------------------------ [2016-08-16 18:09:22] nikic@php.net Reproduce script for at least one issue: <?php function get() { $t = new stdClass; $t->prop = $t; return $t; } $i = 42; get($t)->prop =& $i; The problem here is that get($t)->prop =& $i destroys the stdClass object, but that is also the object to which the assignment happens, so we end up writing a destroyed object. This can be avoided by using an intermediate garbage zval in assign_to_reference. Doing so also fixes the segfault (I only see the one, with and without --diehard) on your test case. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72854 -- Edit this bug report at https://bugs.php.net/bug.php?id=72854&edit=1

« previous php.bugs (#203328) next »