Bug #73933 [Csd->Asn]: error/segfault with ldap_mod_replace and opcache

From: Date: Tue, 17 Jan 2017 12:06:54 +0000
Subject: Bug #73933 [Csd->Asn]: error/segfault with ldap_mod_replace and opcache
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206708@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73933&edit=1

 ID:                 73933
 User updated by:    ryan dot brothers at gmail dot com
 Reported by:        ryan dot brothers at gmail dot com
 Summary:            error/segfault with ldap_mod_replace and opcache
-Status:             Closed
+Status:             Assigned
 Type:               Bug
 Package:            opcache
 Operating System:   Linux
 PHP Version:        7.1.0
 Block user comment: N
 Private report:     N

 New Comment:

laruence - Thank you for the quick fix.  Could you please also check the ldap_modify_batch function?
 I think it's the same problem there with the segfault.  A reproduce script is:

<?php
$ldap = ldap_connect('127.0.0.1', 5000);

ldap_modify_batch($ldap, null, array());

ldap_close($ldap);


Previous Comments:
------------------------------------------------------------------------
[2017-01-17 07:35:55] laruence@php.net

Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=b28c2e20ca83ffb5dc9159d7d03f0baf55b0aeaf
Log: Fixed bug #73933 (error/segfault with ldap_mod_replace and opcache)

------------------------------------------------------------------------
[2017-01-16 13:07:37] nikic@php.net

@laruence: This only separates the outer array. The inner array(s) also need to be separated.

You're right that using zval_get_string() here is inconvenient, because we'd have to
release the strings later.

------------------------------------------------------------------------
[2017-01-16 12:32:25] ryan dot brothers at gmail dot com

laruence - thanks, I'm still seeing the segfault or various errors such as "Invalid
syntax" or "Encoding error" when repeatedly calling the script with your patch.  It
always works the first time, but not later runs.  Using opcache.protect_memory, you should be able
to reproduce the segfault in CLI without having a working LDAP server:

php -n -d zend_extension=opcache.so -d opcache.enable_cli=1 -d opcache.protect_memory=1 ldap.php

<?php
define('AAA', 1);

error_reporting(E_ALL);

$ldap = ldap_connect('127.0.0.1', 5000);

ldap_mod_replace($ldap, null, array(
	'lockoutTime' => array(0),
));

ldap_close($ldap);

------------------------------------------------------------------------
[2017-01-16 03:45:09] laruence@php.net

@nikic didn't notice your comment, it can not be done by changing convert to zval_get_string,
since it require an place to hold the zend_string(ldap using char * directly).

so, separate array is a better way to fix this.

------------------------------------------------------------------------
[2017-01-16 03:37:23] laruence@php.net

I think it is because ldap edit the const array argument in place, please try with the following
patch:

diff --git a/ext/ldap/ldap.c b/ext/ldap/ldap.c
index 4068384..5c1b6da 100644
--- a/ext/ldap/ldap.c
+++ b/ext/ldap/ldap.c
@@ -1427,7 +1427,7 @@ static void php_ldap_do_modify(INTERNAL_FUNCTION_PARAMETERS, int oper)
        zend_ulong index;
        int is_full_add=0; /* flag for full add operation so ldap_mod_add can be put back into oper,
gerrit THomson */

-   if (zend_parse_parameters(ZEND_NUM_ARGS(), "rsa", &link, &dn, &dn_len,
&entry) != SUCCESS) {
+ if (zend_parse_parameters(ZEND_NUM_ARGS(), "rsa/", &link, &dn, &dn_len,
&entry) != SUCCESS) {
                return;
        }


thanks

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=73933


--
Edit this bug report at https://bugs.php.net/bug.php?id=73933&edit=1


Thread (10 messages)

« previous php.bugs (#206708) next »