Bug #76307 [Opn]: strftime format %Z crash php

From: Date: Tue, 15 May 2018 09:25:20 +0000
Subject: Bug #76307 [Opn]: strftime format %Z crash php
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215259@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76307&edit=1

 ID:                 76307
 Updated by:         ab@php.net
 Reported by:        drop_box at live dot de
 Summary:            strftime format %Z crash php
 Status:             Open
 Type:               Bug
 Package:            Date/time related
 Operating System:   Windows 10 1803
 PHP Version:        7.2.5
 Block user comment: N
 Private report:     N

 New Comment:

I've created a VM with this update and German locale. The snippet from the description still
passes, however :/ Lets see for perhaps more comments or more lucky reproducer. Or if you come up
with a patch perhaps, please post. As before, seems it's a bug in the CRT.

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2018-05-14 20:58:45] drop_box at live dot de

After change and recompile the error msg keep the same.
The default locale is:
LC_COLLATE=C;LC_CTYPE=German_Germany.1252;LC_MONETARY=C;LC_NUMERIC=C;LC_TIME=C

------------------------------------------------------------------------
[2018-05-14 10:25:49] ab@php.net

@drop_box, I still have no crash even on the debug build :/ Perhaps it depends on the system locale,
dunno. Which locale is on your machine by default? And nevertheless, since you can compile yourself,
could you please apply the following and see whether it fixes the issue?

diff --git a/ext/date/php_date.c b/ext/date/php_date.c
index 993a7b11cf..1a8f3a8e83 100644
--- a/ext/date/php_date.c
+++ b/ext/date/php_date.c
@@ -1644,7 +1644,7 @@ PHPAPI void php_strftime(INTERNAL_FUNCTION_PARAMETERS, int gmt)
        zend_long            timestamp = 0;
        struct tm            ta;
        int                  max_reallocs = 5;
-       size_t               buf_len = 256, real_len;
+       size_t               buf_len = 512, real_len;
        timelib_time        *ts;
        timelib_tzinfo      *tzi;
        timelib_time_offset *offset = NULL;

Thanks.

------------------------------------------------------------------------
[2018-05-09 13:49:08] drop_box at live dot de

since i got the debug version now,
i get an error message which i think could be helpful:
HEAP CORRUPTION DETECTED: before CRT block (#15222) at 0x0721CDB8.
CRT dectected that the application wrote to memory before start of heap buffer.

Memory allocated at
minkernel\crts\ucrt\src\appcrt\time\strftime.cpp(147).

------------------------------------------------------------------------
[2018-05-09 13:27:02] spam2 at rhsoft dot net

> because i don't understand what the meaning of "debug symbols" is
https://en.wikipedia.org/wiki/Debug_symbol

the debug symbols are what is responsible for outputs like below

php7ts_debug.dll!zif_strftime(_zend_execute_data * execute_data, _zval_struct * return_value) line
1740	C
php7ts_debug.dll!ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER(_zend_execute_data * execute_data) line
617	C

------------------------------------------------------------------------
[2018-05-09 13:17:41] drop_box at live dot de

I also install in the meantime the update: KB4103721
but nothing changed in my eyes (as you see on my backtrace/crash report)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=76307


--
Edit this bug report at https://bugs.php.net/bug.php?id=76307&edit=1


Thread (18 messages)

« previous php.bugs (#215259) next »