Sec Bug->Bug #73677 [Nab]: Generating phar.phar core dump with gcc ASAN enabled build
| From: | stas@php.net | Date: | Wed, 15 Feb 2017 22:15:56 +0000 |
| Subject: | Sec Bug->Bug #73677 [Nab]: Generating phar.phar core dump with gcc ASAN enabled build | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207394@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73677&edit=1
ID: 73677
Updated by: stas@php.net
Reported by: ondrej@php.net
Summary: Generating phar.phar core dump with gcc ASAN enabled
build
Status: Not a bug
-Type: Security
+Type: Bug
Package: PHAR related
Operating System: Linux
PHP Version: 7.0.13
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2017-02-15 20:55:16] ondrej@php.net
I think this whole report should not be private, as this is a condition caused by AddressSanitizer.
Feel free to do a PR, or I will do that.
As far as I understand the effect of RTLD_DEEPBIND, it only affects the symbol ordering with
DEEPBIND preferring symbols from the .so library to the global symbols.
So in theory, it might have some side effects, but we are talking about builds with AddressSanitizer
only here, and this is not expected to run in a production environment.
------------------------------------------------------------------------
[2017-02-15 20:48:36] stas@php.net
Since this patch is not security-sensitive, I'd submit it as pull request, and if nobody
objects, I think it's ok to merge it. Would like more eyes on it since I'm not 100% sure
what is the effect of disabling RTLD_DEEPBIND.
------------------------------------------------------------------------
[2017-02-15 10:23:41] ondrej@php.net
Turns out AddressSanitizer is not compatible with RTLD_DEEPBIND, so simple patch like this should
fix the -fsanitize=address builds:
From: =?utf-8?q?Ond=C5=99ej_Sur=C3=BD?= <ondrej@sury.org>
Date: Wed, 15 Feb 2017 11:06:08 +0100
Subject: Disable RTLD_DEEPBIND for ASAN builds
---
Zend/zend_portability.h | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/Zend/zend_portability.h b/Zend/zend_portability.h
index c1e17c30f..dd4fcdc84 100644
--- a/Zend/zend_portability.h
+++ b/Zend/zend_portability.h
@@ -131,6 +131,12 @@
#if defined(HAVE_LIBDL) && !defined(ZEND_WIN32)
+# if defined(__has_feature)
+# if __has_feature(address_sanitizer)
+# define __SANITIZE_ADDRESS__)
+# endif
+# endif
+
# ifndef RTLD_LAZY
# define RTLD_LAZY 1 /* Solaris 1, FreeBSD's (2.1.7.1 and older) */
# endif
@@ -141,7 +147,7 @@
# if defined(RTLD_GROUP) && defined(RTLD_WORLD) && defined(RTLD_PARENT)
# define DL_LOAD(libname) dlopen(libname, RTLD_LAZY | RTLD_GLOBAL | RTLD_GROUP
| RTLD_WORLD | RTLD_PARENT)
-# elif defined(RTLD_DEEPBIND)
+# elif defined(RTLD_DEEPBIND) && !defined(__SANITIZE_ADDRESS__)
# define DL_LOAD(libname) dlopen(libname, RTLD_LAZY | RTLD_GLOBAL |
RTLD_DEEPBIND)
# else
# define DL_LOAD(libname) dlopen(libname, RTLD_LAZY | RTLD_GLOBAL)
------------------------------------------------------------------------
[2017-01-16 08:07:25] stas@php.net
Looks like not a PHP issue. Please reopen if it turns out otherwise.
------------------------------------------------------------------------
[2017-01-10 14:58:52] ondrej@php.net
I have reported this as https://github.com/google/sanitizers/issues/760,
as I am more and more convinced that this is a bug in AddressSanitizer.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73677
--
Edit this bug report at https://bugs.php.net/bug.php?id=73677&edit=1