Bug #76275 [Ana->Csd]: Assertion failure in file cache when unserializing empty try_catch_array

From: Date: Fri, 27 Apr 2018 15:09:11 +0000
Subject: Bug #76275 [Ana->Csd]: Assertion failure in file cache when unserializing empty try_catch_array
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214940@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76275&edit=1 ID: 76275 Updated by: nikic@php.net Reported by: mate at sla dot hu Summary: Assertion failure in file cache when unserializing empty try_catch_array -Status: Analyzed +Status: Closed Type: Bug Package: opcache Operating System: ubuntu 16 PHP Version: 7.2.5 Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=279ba58edbd0454d7e534e223e3538a2b0b5ff9b Log: Fixed bug #76275 Previous Comments: ------------------------------------------------------------------------ [2018-04-27 09:14:29] nikic@php.net The issue is that the try_catch_array allocation is empty and points at the very end of the script memory. In serialized form, that means ptr == script->size. However, IS_SERIALIZED requires ptr < script->size. I think we should do two things here: a) Allow ptr <= script->size to allow empty allocations. Theoretically this could clash with a new allocation starting at memory address script->size, but that seems rather unlikely to me. b) Prevent this particular empty allocation from occurring. As an alternative to a) we could also assert in the opcache allocator that empty allocations are not allowed, thus catching this earlier. ------------------------------------------------------------------------ [2018-04-27 08:21:54] mate at sla dot hu Description: ------------ code below stripped from paragonie/random_compat/lib/random.php this my first compilation on 16.04 gcc toolchain, and i dont know my toolchain has a problem, or this is a bug, becaouse the original downloaded binary version works without problem on this file, but my compilation fails $_main: ; (lines=1, args=0, vars=0, tmps=0) ; (after optimizer) ; /home/sla/workspace/its3/test6.php:1-22 L0 (4): RETURN null random_bytes: ; (lines=6, args=1, vars=1, tmps=1) ; (after optimizer) ; /home/sla/workspace/its3/test6.php:12-19 L0 (12): CV0($length) = RECV 1 L1 (14): UNSET_CV CV0($length) L2 (15): V1 = NEW 1 string("Exception") L3 (16): SEND_VAL_EX string("There is no suitable CSPRNG installed on your system") 1 L4 (16): DO_FCALL L5 (16): THROW V1 php: /home/mate/php-7.2.5/ext/opcache/zend_file_cache.c:506: zend_file_cache_serialize_op_array: Assertion `(((char*)(op_array->try_catch_array) >= (char*)script->mem && (char*)(op_array->try_catch_array) < (char*)script->mem + script->size) || ((char*)(op_array->try_catch_array) >= (accel_shared_globals->interned_strings_start) && (char*)(op_array->try_catch_array) < (accel_shared_globals->interned_strings_end)))' failed. Aborted (core dumped) Test script: --------------- <?php if (PHP_VERSION_ID >= 70000) { return; } if (!is_callable('random_bytes')) { try { } catch (com_exception $e) { } function random_bytes($length) { unset($length); // Suppress "variable not used" warnings. throw new Exception( 'There is no suitable CSPRNG installed on your system' ); return ''; } } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76275&edit=1

« previous php.bugs (#214940) next »