Bug #76275 [Opn->Ana]: assert

From: Date: Fri, 27 Apr 2018 09:14:35 +0000
Subject: Bug #76275 [Opn->Ana]: assert
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214922@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76275&edit=1 ID: 76275 Updated by: nikic@php.net Reported by: mate at sla dot hu Summary: assert -Status: Open +Status: Analyzed Type: Bug Package: opcache Operating System: ubuntu 16 PHP Version: 7.2.5 Block user comment: N Private report: N New Comment: The issue is that the try_catch_array allocation is empty and points at the very end of the script memory. In serialized form, that means ptr == script->size. However, IS_SERIALIZED requires ptr < script->size. I think we should do two things here: a) Allow ptr <= script->size to allow empty allocations. Theoretically this could clash with a new allocation starting at memory address script->size, but that seems rather unlikely to me. b) Prevent this particular empty allocation from occurring. As an alternative to a) we could also assert in the opcache allocator that empty allocations are not allowed, thus catching this earlier. Previous Comments: ------------------------------------------------------------------------ [2018-04-27 08:21:54] mate at sla dot hu Description: ------------ code below stripped from paragonie/random_compat/lib/random.php this my first compilation on 16.04 gcc toolchain, and i dont know my toolchain has a problem, or this is a bug, becaouse the original downloaded binary version works without problem on this file, but my compilation fails $_main: ; (lines=1, args=0, vars=0, tmps=0) ; (after optimizer) ; /home/sla/workspace/its3/test6.php:1-22 L0 (4): RETURN null random_bytes: ; (lines=6, args=1, vars=1, tmps=1) ; (after optimizer) ; /home/sla/workspace/its3/test6.php:12-19 L0 (12): CV0($length) = RECV 1 L1 (14): UNSET_CV CV0($length) L2 (15): V1 = NEW 1 string("Exception") L3 (16): SEND_VAL_EX string("There is no suitable CSPRNG installed on your system") 1 L4 (16): DO_FCALL L5 (16): THROW V1 php: /home/mate/php-7.2.5/ext/opcache/zend_file_cache.c:506: zend_file_cache_serialize_op_array: Assertion `(((char*)(op_array->try_catch_array) >= (char*)script->mem && (char*)(op_array->try_catch_array) < (char*)script->mem + script->size) || ((char*)(op_array->try_catch_array) >= (accel_shared_globals->interned_strings_start) && (char*)(op_array->try_catch_array) < (accel_shared_globals->interned_strings_end)))' failed. Aborted (core dumped) Test script: --------------- <?php if (PHP_VERSION_ID >= 70000) { return; } if (!is_callable('random_bytes')) { try { } catch (com_exception $e) { } function random_bytes($length) { unset($length); // Suppress "variable not used" warnings. throw new Exception( 'There is no suitable CSPRNG installed on your system' ); return ''; } } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76275&edit=1

« previous php.bugs (#214922) next »