Bug #77447 [Ver]: PHP 7.3 built with ASAN crashes in zend_cpu_supports_avx2
| From: | nikic@php.net | Date: | Mon, 14 Jan 2019 10:31:47 +0000 |
| Subject: | Bug #77447 [Ver]: PHP 7.3 built with ASAN crashes in zend_cpu_supports_avx2 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218935@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77447&edit=1
ID: 77447
Updated by: nikic@php.net
Reported by: hanno at hboeck dot de
Summary: PHP 7.3 built with ASAN crashes in
zend_cpu_supports_avx2
Status: Verified
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: 7.3.1
Block user comment: N
Private report: N
New Comment:
Looks like asan being incompatible with ifunc resolvers is a longstanding problem: https://github.com/google/sanitizers/issues/342
We might be able to work around it with some __attribute__((no_sanitize_address)) attributes.
Previous Comments:
------------------------------------------------------------------------
[2019-01-14 10:24:35] nikic@php.net
0x555555c21f56 <zend_cpu_supports_sse42+4> callq 0x555555832560
<__cpu_indicator_init>
0x555555c21f5b <zend_cpu_supports_sse42+9> lea 0xb6971e(%rip),%rax
0x555555c21f62 <zend_cpu_supports_sse42+16> lea 0xc(%rax),%rax
0x555555c21f66 <zend_cpu_supports_sse42+20> mov %rax,%rdx
0x555555c21f69 <zend_cpu_supports_sse42+23> shr $0x3,%rdx
0x555555c21f6d <zend_cpu_supports_sse42+27> add $0x7fff8000,%rdx
> 0x555555c21f74 <zend_cpu_supports_sse42+34> movzbl (%rdx),%edx
(gdb) p &__cpu_model
$8 = (<data variable, no debug info> *) 0x55555678b680 <__cpu_model>
(gdb) p/x $rax
$9 = 0x55555678b68c
(gdb) p/x $rdx
$10 = 0xaab2ace96d1
From what I gathered (addr>>3)+0x7fff8000 is the shadow address used by asan, and apparently
it is not mapped.
------------------------------------------------------------------------
[2019-01-14 09:56:19] nikic@php.net
Confirming the segfault. Had to add LIBS="-ldl" to avoid linker errors.
------------------------------------------------------------------------
[2019-01-11 14:59:05] hanno at hboeck dot de
Description:
------------
I'm unable to get PHP 7.3 to run with address sanitizer.
Reproduce:
./configure CFLAGS="-fsanitize=address -g" CXXFLAGS="-fsanitize=address -g"
LDFLAGS="-fsanitize=address" --enable-debug
make
./sapi/cli/php
leads to a segfault.
This problem does not happen with 7.2.x.
Address Sanitizer has been an extremely helpful tool to identify memory corruption bugs and security
issues in PHP, therefore this is concerning, as it might hamper the ability of security researchers
to find bugs in PHP.
A stack trace from GDB shows this happens in the function zend_cpu_supports_avx2(). AVX2 support is
not available in PHP 7.2, therefore I believe this explains the difference between 7.2 and 7.3.
Expected result:
----------------
No segfault with ASAN.
Actual result:
--------------
Segfault with ASAN.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77447&edit=1