Bug #76275 [Ana->Csd]: Assertion failure in file cache when unserializing empty try_catch_array
| From: | nikic@php.net | Date: | Fri, 27 Apr 2018 15:09:11 +0000 |
| Subject: | Bug #76275 [Ana->Csd]: Assertion failure in file cache when unserializing empty try_catch_array | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214940@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76275&edit=1
ID: 76275
Updated by: nikic@php.net
Reported by: mate at sla dot hu
Summary: Assertion failure in file cache when unserializing
empty try_catch_array
-Status: Analyzed
+Status: Closed
Type: Bug
Package: opcache
Operating System: ubuntu 16
PHP Version: 7.2.5
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=279ba58edbd0454d7e534e223e3538a2b0b5ff9b
Log: Fixed bug #76275
Previous Comments:
------------------------------------------------------------------------
[2018-04-27 09:14:29] nikic@php.net
The issue is that the try_catch_array allocation is empty and points at the very end of the script
memory. In serialized form, that means ptr == script->size. However, IS_SERIALIZED requires ptr
< script->size.
I think we should do two things here:
a) Allow ptr <= script->size to allow empty allocations. Theoretically this could clash with
a new allocation starting at memory address script->size, but that seems rather unlikely to me.
b) Prevent this particular empty allocation from occurring.
As an alternative to a) we could also assert in the opcache allocator that empty allocations are not
allowed, thus catching this earlier.
------------------------------------------------------------------------
[2018-04-27 08:21:54] mate at sla dot hu
Description:
------------
code below stripped from paragonie/random_compat/lib/random.php
this my first compilation on 16.04 gcc toolchain, and i dont know my toolchain has a problem, or
this is a bug, becaouse the original downloaded binary version works without problem on this file,
but my compilation fails
$_main: ; (lines=1, args=0, vars=0, tmps=0)
; (after optimizer)
; /home/sla/workspace/its3/test6.php:1-22
L0 (4): RETURN null
random_bytes: ; (lines=6, args=1, vars=1, tmps=1)
; (after optimizer)
; /home/sla/workspace/its3/test6.php:12-19
L0 (12): CV0($length) = RECV 1
L1 (14): UNSET_CV CV0($length)
L2 (15): V1 = NEW 1 string("Exception")
L3 (16): SEND_VAL_EX string("There is no suitable CSPRNG installed on your system") 1
L4 (16): DO_FCALL
L5 (16): THROW V1
php: /home/mate/php-7.2.5/ext/opcache/zend_file_cache.c:506: zend_file_cache_serialize_op_array:
Assertion `(((char*)(op_array->try_catch_array) >= (char*)script->mem &&
(char*)(op_array->try_catch_array) < (char*)script->mem + script->size) ||
((char*)(op_array->try_catch_array) >= (accel_shared_globals->interned_strings_start)
&& (char*)(op_array->try_catch_array) <
(accel_shared_globals->interned_strings_end)))' failed.
Aborted (core dumped)
Test script:
---------------
<?php
if (PHP_VERSION_ID >= 70000) {
return;
}
if (!is_callable('random_bytes')) {
try {
} catch (com_exception $e) {
}
function random_bytes($length)
{
unset($length); // Suppress "variable not used" warnings.
throw new Exception(
'There is no suitable CSPRNG installed on your system'
);
return '';
}
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76275&edit=1