Bug #74310 [Ana->Asn]: segfault in i_zval_ptr_dtor()

From: Date: Tue, 24 Oct 2017 05:16:48 +0000
Subject: Bug #74310 [Ana->Asn]: segfault in i_zval_ptr_dtor()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211921@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74310&edit=1

 ID:                 74310
 Updated by:         kalle@php.net
 Reported by:        brian dot carpenter at gmail dot com
 Summary:            segfault in i_zval_ptr_dtor()
-Status:             Analyzed
+Status:             Assigned
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Debian 8 x64
 PHP Version:        7.1Git-2017-03-24 (Git)
 Assigned To:        pollita
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2017-09-10 21:34:53] cmb@php.net

Related To: Bug #74593

------------------------------------------------------------------------
[2017-03-27 22:10:26] pollita@php.net

Sort of...

It's happening because a zval referencing a free'd string is being dtor'd (in the
middle of a bailout).

I've got a fix for the problem and will push it when I finish testing edge cases.

------------------------------------------------------------------------
[2017-03-26 17:09:20] bwoebi@php.net

This happens as the refcount is decremented, but the assignment to the new value never happening,
thus leaving us with a zend_string with two references but rc=1.

A trivial fix would be:
https://bugs.php.net/patch-display.php?bug_id=74310&patch=bug_74310_decrement_after_alloc&revision=latest

But I'm not sure whether that's the ideal fix though.

------------------------------------------------------------------------
[2017-03-26 17:08:41] bwoebi@php.net

The following patch has been added/updated:

Patch Name: bug_74310_decrement_after_alloc
Revision:   1490548119
URL:        https://bugs.php.net/patch-display.php?bug=74310&patch=bug_74310_decrement_after_alloc&revision=1490548119

------------------------------------------------------------------------
[2017-03-25 22:29:29] pollita@php.net

I've been able to reduce the repro script to the following.  When I gdb, it still crashes,
apparently while trying to clean up the global symbol table at request end.

<?
$o{8}='800000000';
$$o{'8000000'}=$Array='Q';
$$o{'800000000'}=$$Array=0;

Interestingly, shortening the keys (while keeping them unique) *does* avoid the crash.

(gdb) bt
#0  0x00000000009a006c in i_zval_ptr_dtor (zval_ptr=0x7fffef01e090, 
    __zend_filename=0x10d7148 "/home/sgolemon/dev/php/php-src/Zend/zend_execute_API.c", 
    __zend_lineno=212) at /home/sgolemon/dev/php/php-src/Zend/zend_variables.h:48
#1  0x00000000009a0c5c in zend_unclean_zval_ptr_dtor (zv=0x7fffef01e090)
    at /home/sgolemon/dev/php/php-src/Zend/zend_execute_API.c:212
#2  0x00000000009d2893 in _zend_hash_del_el_ex (ht=0x1452d90 <executor_globals+304>, idx=8, 
    p=0x7fffef063200, prev=0x0) at /home/sgolemon/dev/php/php-src/Zend/zend_hash.c:997
#3  0x00000000009d2973 in _zend_hash_del_el (ht=0x1452d90 <executor_globals+304>, idx=8, 
    p=0x7fffef063200) at /home/sgolemon/dev/php/php-src/Zend/zend_hash.c:1020
#4  0x00000000009d3ef8 in zend_hash_graceful_reverse_destroy (
    ht=0x1452d90 <executor_globals+304>) at
/home/sgolemon/dev/php/php-src/Zend/zend_hash.c:1476
#5  0x00000000009a0f86 in shutdown_executor ()
    at /home/sgolemon/dev/php/php-src/Zend/zend_execute_API.c:281
#6  0x00000000009bbc73 in zend_deactivate () at /home/sgolemon/dev/php/php-src/Zend/zend.c:1060
#7  0x0000000000921857 in php_request_shutdown (dummy=0x0)
    at /home/sgolemon/dev/php/php-src/main/main.c:1879
#8  0x0000000000aa848b in do_cli (argc=2, argv=0x1457d20)
    at /home/sgolemon/dev/php/php-src/sapi/cli/php_cli.c:1164
#9  0x0000000000aa8cf9 in main (argc=2, argv=0x1457d20)
    at /home/sgolemon/dev/php/php-src/sapi/cli/php_cli.c:1390

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=74310


--
Edit this bug report at https://bugs.php.net/bug.php?id=74310&edit=1


Thread (9 messages)

« previous php.bugs (#211921) next »