Bug #76594 [Opn]: Bus Error due to unaligned access in zend_ini.c OnUpdateLong
| From: | rainer dot jung at kippdata dot de | Date: | Sun, 08 Jul 2018 12:45:15 +0000 |
| Subject: | Bug #76594 [Opn]: Bus Error due to unaligned access in zend_ini.c OnUpdateLong | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-216216@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76594&edit=1
ID: 76594
User updated by: rainer dot jung at kippdata dot de
Reported by: rainer dot jung at kippdata dot de
Summary: Bus Error due to unaligned access in zend_ini.c
OnUpdateLong
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Solaris Sparc 32 Bit
PHP Version: 7.3.0alpha3
Block user comment: N
Private report: N
New Comment:
It does not happen for 7.2.7. I did not test any 7.3 alpha before.
Compiler is gcc 7.3.0.
Bus errors due to bad alignment are well-lknown on Solaris. I didn't find the code that sets
mh_arg1 to 97 (decimal).
Previous Comments:
------------------------------------------------------------------------
[2018-07-08 12:30:29] cmb@php.net
Is this a regression in PHP 7.3, or does it happen with earlier
versions also?
Which compiler do you use?
------------------------------------------------------------------------
[2018-07-08 03:18:47] rainer dot jung at kippdata dot de
Description:
------------
I get a bus error for most of the PHP tests. An easy example is test004.sh.
The Solaris Sparc platform is sensitive to correct alignment for 32 bit and 64 bit types. They must
be aligned on corresponding address boundaries, which is not true in the case of these crashes.
The crash happens for 32 Bit builds in Zend/zend_ini.c:671 (OnUpdateLong):
669 p = (zend_long *) (base+(size_t) mh_arg1);
670
671 *p = zend_atol(ZSTR_VAL(new_value), ZSTR_LEN(new_value));
Here the address p is:
p = 0xfb1f63d5 <mbstring_globals+97>
base = 0xfb1f6374 <mbstring_globals> ""
which is an odd address. Since on this platform zend_long has size 4 (bytes) this would need to be
divisible by 4. The value for mh_arg1 comes from the next frame Zend/zend_ini.c:269
(zend_register_ini_entries):
268 if (p->on_modify) {
269 p->on_modify(p, p->value, p->mh_arg1, p->mh_arg2, p->mh_arg3,
ZEND_INI_STAGE_STARTUP);
270 }
There p is:
{name = 0x186760, on_modify = 0xfee87aa8 <OnUpdateLong>, mh_arg1 = 0x61, mh_arg2 = 0xfb276374
<mbstring_globals>, mh_arg3 = 0x0, value = 0x3de70, orig_value = 0x0,
displayer = 0x384b8 <zend_ini_boolean_displayer_cb@plt>, module_number = 30, modifiable = 7
'\a', orig_modifiable = 0 '\000', modified = 0 '\000'}
and mh_arg1 is set in
241 p->mh_arg1 = ini_entry->mh_arg1;
This is ini_entry:
{name = 0xfb246a80 "mbstring.strict_detection", on_modify = 0xfee87aa8
<OnUpdateLong>, mh_arg1 = 0x61, mh_arg2 = 0xfb276374 <mbstring_globals>, mh_arg3 = 0x0,
value = 0xfb246a38 "0", displayer = 0x384b8 <zend_ini_boolean_displayer_cb@plt>,
value_length = 1, name_length = 25, modifiable = 7 '\a'}
The next frame is ext/mbstring/mbstring.c:1579 (zm_startup_mbstring):
1579 REGISTER_INI_ENTRIES();
The crash does not happen or Linux on x86_64 platforms with 64 bit builds. These platforms are less
sensitive for misalignment.
Regards,
Rainer
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76594&edit=1