Sec Bug->Bug #73677 [Nab]: Generating phar.phar core dump with gcc ASAN enabled build

From: Date: Wed, 15 Feb 2017 22:15:56 +0000
Subject: Sec Bug->Bug #73677 [Nab]: Generating phar.phar core dump with gcc ASAN enabled build
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207394@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73677&edit=1 ID: 73677 Updated by: stas@php.net Reported by: ondrej@php.net Summary: Generating phar.phar core dump with gcc ASAN enabled build Status: Not a bug -Type: Security +Type: Bug Package: PHAR related Operating System: Linux PHP Version: 7.0.13 Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2017-02-15 20:55:16] ondrej@php.net I think this whole report should not be private, as this is a condition caused by AddressSanitizer. Feel free to do a PR, or I will do that. As far as I understand the effect of RTLD_DEEPBIND, it only affects the symbol ordering with DEEPBIND preferring symbols from the .so library to the global symbols. So in theory, it might have some side effects, but we are talking about builds with AddressSanitizer only here, and this is not expected to run in a production environment. ------------------------------------------------------------------------ [2017-02-15 20:48:36] stas@php.net Since this patch is not security-sensitive, I'd submit it as pull request, and if nobody objects, I think it's ok to merge it. Would like more eyes on it since I'm not 100% sure what is the effect of disabling RTLD_DEEPBIND. ------------------------------------------------------------------------ [2017-02-15 10:23:41] ondrej@php.net Turns out AddressSanitizer is not compatible with RTLD_DEEPBIND, so simple patch like this should fix the -fsanitize=address builds: From: =?utf-8?q?Ond=C5=99ej_Sur=C3=BD?= <ondrej@sury.org> Date: Wed, 15 Feb 2017 11:06:08 +0100 Subject: Disable RTLD_DEEPBIND for ASAN builds --- Zend/zend_portability.h | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/Zend/zend_portability.h b/Zend/zend_portability.h index c1e17c30f..dd4fcdc84 100644 --- a/Zend/zend_portability.h +++ b/Zend/zend_portability.h @@ -131,6 +131,12 @@ #if defined(HAVE_LIBDL) && !defined(ZEND_WIN32) +# if defined(__has_feature) +# if __has_feature(address_sanitizer) +# define __SANITIZE_ADDRESS__) +# endif +# endif + # ifndef RTLD_LAZY # define RTLD_LAZY 1 /* Solaris 1, FreeBSD's (2.1.7.1 and older) */ # endif @@ -141,7 +147,7 @@ # if defined(RTLD_GROUP) && defined(RTLD_WORLD) && defined(RTLD_PARENT) # define DL_LOAD(libname) dlopen(libname, RTLD_LAZY | RTLD_GLOBAL | RTLD_GROUP | RTLD_WORLD | RTLD_PARENT) -# elif defined(RTLD_DEEPBIND) +# elif defined(RTLD_DEEPBIND) && !defined(__SANITIZE_ADDRESS__) # define DL_LOAD(libname) dlopen(libname, RTLD_LAZY | RTLD_GLOBAL | RTLD_DEEPBIND) # else # define DL_LOAD(libname) dlopen(libname, RTLD_LAZY | RTLD_GLOBAL) ------------------------------------------------------------------------ [2017-01-16 08:07:25] stas@php.net Looks like not a PHP issue. Please reopen if it turns out otherwise. ------------------------------------------------------------------------ [2017-01-10 14:58:52] ondrej@php.net I have reported this as https://github.com/google/sanitizers/issues/760, as I am more and more convinced that this is a bug in AddressSanitizer. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73677 -- Edit this bug report at https://bugs.php.net/bug.php?id=73677&edit=1

« previous php.bugs (#207394) next »