Bug #52752 [Com]: Crash when lexing

From: Date: Mon, 28 May 2018 19:42:08 +0000
Subject: Bug #52752 [Com]: Crash when lexing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215399@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=52752&edit=1

 ID:                 52752
 Comment by:         poonandrew88 at hotmail dot com
 Reported by:        paulgao at yeah dot net
 Summary:            Crash when lexing
 Status:             Verified
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Centos 5 32bit
 PHP Version:        5.3SVN-2010-08-31 (SVN)
 Block user comment: N
 Private report:     N

 New Comment:

Also reproducible on Amazon Linux PHP 5.6.36. Our production httpds also crash every day.


Previous Comments:
------------------------------------------------------------------------
[2017-12-23 12:13:08] nikic@php.net

Related To: Bug #71651

------------------------------------------------------------------------
[2017-12-23 11:08:53] nikic@php.net

Related To: Bug #74359

------------------------------------------------------------------------
[2017-12-23 11:08:35] nikic@php.net

Related To: Bug #71377

------------------------------------------------------------------------
[2017-06-25 23:46:39] zac at sprackett dot com

Patch for php 5.6.30 is here:

https://gist.github.com/zsprackett/8197f0242040c2e43d8d800521f09e22

------------------------------------------------------------------------
[2017-06-21 17:56:27] zac at sprackett dot com

This patch seems to help in my case.


diff -ruN php-5.6.30/Zend/zend_language_scanner.c php-5.6.30.patched/Zend/zend_language_scanner.c
--- php-5.6.30/Zend/zend_language_scanner.c	2017-01-18 19:17:47.000000000 -0500
+++ php-5.6.30.patched/Zend/zend_language_scanner.c	2017-06-21 13:18:53.000000000 -0400
@@ -125,6 +125,14 @@
 
 BEGIN_EXTERN_C()
 
+#ifndef _WIN32
+static sigjmp_buf sigbus_jmpbuf;
+static void sigbus_handler (int sig, siginfo_t *siginfo, void *ptr)
+{
+  siglongjmp(sigbus_jmpbuf, 1);
+}
+#endif
+
 static size_t encoding_filter_script_to_internal(unsigned char **to, size_t *to_length, const
unsigned char *from, size_t from_length TSRMLS_DC)
 {
 	const zend_encoding *internal_encoding = zend_multibyte_get_internal_encoding(TSRMLS_C);
@@ -580,6 +588,36 @@
 		}
 		compilation_successful=0;
 	} else {
+#ifndef _WIN32
+    struct sigaction sigbus_signal;
+    struct sigaction old_sigbus_signal;
+
+    memset(&sigbus_signal, 0, sizeof(sigbus_signal));
+    memset(&old_sigbus_signal, 0, sizeof(old_sigbus_signal));
+    sigbus_signal.sa_sigaction = sigbus_handler;
+    sigbus_signal.sa_flags = SA_SIGINFO;
+#endif
+
+#if defined(ZEND_SIGNALS) && !defined(_WIN32)
+    zend_try { zend_sigaction(SIGBUS, &sigbus_signal, &old_sigbus_signal TSRMLS_CC); }
zend_end_try();
+#elif !defined(_WIN32)
+    sigaction(SIGBUS, &sigbus_signal, &old_sigbus_signal);
+#endif
+
+#ifndef _WIN32
+    if (sigsetjmp(sigbus_jmpbuf, 1)) {
+			if (file_handle->type != ZEND_HANDLE_STREAM) {
+				file_handle->type = ZEND_HANDLE_STREAM;
+			}
+    }
+#endif
+
 		init_op_array(op_array, ZEND_USER_FUNCTION, INITIAL_OP_ARRAY_SIZE TSRMLS_CC);
 		CG(in_compilation) = 1;
 		CG(active_op_array) = op_array;
@@ -592,6 +630,13 @@
 			zend_bailout();
 		}
 		compilation_successful=1;
+
+#if defined(ZEND_SIGNALS) && !defined(_WIN32)
+  zend_try { zend_sigaction(SIGBUS, &old_sigbus_signal, 0 TSRMLS_CC); } zend_end_try();
+#elif !defined(_WIN32)
+  sigaction(SIGBUS, &old_sigbus_signal, 0);
+#endif
+
 	}
 
 	if (retval) {
diff -ruN php-5.6.30/Zend/zend_language_scanner.l php-5.6.30.patched/Zend/zend_language_scanner.l
--- php-5.6.30/Zend/zend_language_scanner.l	2017-01-18 19:17:47.000000000 -0500
+++ php-5.6.30.patched/Zend/zend_language_scanner.l	2017-06-21 13:18:38.000000000 -0400
@@ -123,6 +123,14 @@
 
 BEGIN_EXTERN_C()
 
+#ifndef _WIN32
+static sigjmp_buf sigbus_jmpbuf;
+static void sigbus_handler (int sig, siginfo_t *siginfo, void *ptr)
+{
+	siglongjmp(sigbus_jmpbuf, 1);
+}
+#endif
+ 
 static size_t encoding_filter_script_to_internal(unsigned char **to, size_t *to_length, const
unsigned char *from, size_t from_length TSRMLS_DC)
 {
 	const zend_encoding *internal_encoding = zend_multibyte_get_internal_encoding(TSRMLS_C);
@@ -578,6 +586,34 @@
 		}
 		compilation_successful=0;
 	} else {
+#ifndef _WIN32
+		struct sigaction sigbus_signal;
+		struct sigaction old_sigbus_signal;
+
+		memset(&sigbus_signal, 0, sizeof(sigbus_signal));
+		memset(&old_sigbus_signal, 0, sizeof(old_sigbus_signal));
+		sigbus_signal.sa_sigaction = sigbus_handler;
+		sigbus_signal.sa_flags = SA_SIGINFO;
+#endif
+
+#if defined(ZEND_SIGNALS) && !defined(_WIN32)
+		zend_try { zend_sigaction(SIGBUS, &sigbus_signal, &old_sigbus_signal TSRMLS_CC); }
zend_end_try();
+#elif !defined(_WIN32)
+		sigaction(SIGBUS, &sigbus_signal, &old_sigbus_signal);
+#endif
+
+#ifndef _WIN32
+		if (sigsetjmp(sigbus_jmpbuf, 1)) {
+			file_handle->type = ZEND_HANDLE_STREAM;
+		}
+#endif
+
 		init_op_array(op_array, ZEND_USER_FUNCTION, INITIAL_OP_ARRAY_SIZE TSRMLS_CC);
 		CG(in_compilation) = 1;
 		CG(active_op_array) = op_array;
@@ -590,6 +626,12 @@
 			zend_bailout();
 		}
 		compilation_successful=1;
+
+#if defined(ZEND_SIGNALS) && !defined(_WIN32)
+		zend_try { zend_sigaction(SIGBUS, &old_sigbus_signal, 0 TSRMLS_CC); } zend_end_try();
+#elif !defined(_WIN32)
+		sigaction(SIGBUS, &old_sigbus_signal, 0);
+#endif
 	}
 
 	if (retval) {

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=52752


--
Edit this bug report at https://bugs.php.net/bug.php?id=52752&edit=1


Thread (44 messages)

« previous php.bugs (#215399) next »