Bug #77447 [Csd]: PHP 7.3 built with ASAN crashes in zend_cpu_supports_avx2
| From: | hanno at hboeck dot de | Date: | Wed, 16 Jan 2019 11:56:57 +0000 |
| Subject: | Bug #77447 [Csd]: PHP 7.3 built with ASAN crashes in zend_cpu_supports_avx2 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218986@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77447&edit=1
ID: 77447
User updated by: hanno at hboeck dot de
Reported by: hanno at hboeck dot de
Summary: PHP 7.3 built with ASAN crashes in
zend_cpu_supports_avx2
Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: 7.3.1
Block user comment: N
Private report: N
New Comment:
I tried patching 7.3.1 with that commit and it still crashes for me, so I don't believe this is
fixed.
Previous Comments:
------------------------------------------------------------------------
[2019-01-14 10:45:44] nikic@php.net
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=c8c5a3ab8afdaa4692784a54a678cc565ecd1834
Log: Fixed bug #77447
------------------------------------------------------------------------
[2019-01-14 10:31:47] nikic@php.net
Looks like asan being incompatible with ifunc resolvers is a longstanding problem: https://github.com/google/sanitizers/issues/342
We might be able to work around it with some __attribute__((no_sanitize_address)) attributes.
------------------------------------------------------------------------
[2019-01-14 10:24:35] nikic@php.net
0x555555c21f56 <zend_cpu_supports_sse42+4> callq 0x555555832560
<__cpu_indicator_init>
0x555555c21f5b <zend_cpu_supports_sse42+9> lea 0xb6971e(%rip),%rax
0x555555c21f62 <zend_cpu_supports_sse42+16> lea 0xc(%rax),%rax
0x555555c21f66 <zend_cpu_supports_sse42+20> mov %rax,%rdx
0x555555c21f69 <zend_cpu_supports_sse42+23> shr $0x3,%rdx
0x555555c21f6d <zend_cpu_supports_sse42+27> add $0x7fff8000,%rdx
> 0x555555c21f74 <zend_cpu_supports_sse42+34> movzbl (%rdx),%edx
(gdb) p &__cpu_model
$8 = (<data variable, no debug info> *) 0x55555678b680 <__cpu_model>
(gdb) p/x $rax
$9 = 0x55555678b68c
(gdb) p/x $rdx
$10 = 0xaab2ace96d1
From what I gathered (addr>>3)+0x7fff8000 is the shadow address used by asan, and apparently
it is not mapped.
------------------------------------------------------------------------
[2019-01-14 09:56:19] nikic@php.net
Confirming the segfault. Had to add LIBS="-ldl" to avoid linker errors.
------------------------------------------------------------------------
[2019-01-11 14:59:05] hanno at hboeck dot de
Description:
------------
I'm unable to get PHP 7.3 to run with address sanitizer.
Reproduce:
./configure CFLAGS="-fsanitize=address -g" CXXFLAGS="-fsanitize=address -g"
LDFLAGS="-fsanitize=address" --enable-debug
make
./sapi/cli/php
leads to a segfault.
This problem does not happen with 7.2.x.
Address Sanitizer has been an extremely helpful tool to identify memory corruption bugs and security
issues in PHP, therefore this is concerning, as it might hamper the ability of security researchers
to find bugs in PHP.
A stack trace from GDB shows this happens in the function zend_cpu_supports_avx2(). AVX2 support is
not available in PHP 7.2, therefore I believe this explains the difference between 7.2 and 7.3.
Expected result:
----------------
No segfault with ASAN.
Actual result:
--------------
Segfault with ASAN.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77447&edit=1