Bug #78173 [PATCH]: XML-RPC mutates immutable objects during encoding
| From: | asher.baker@tripleplay.tv | Date: | Tue, 18 Jun 2019 14:13:50 +0000 |
| Subject: | Bug #78173 [PATCH]: XML-RPC mutates immutable objects during encoding | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221369@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78173&edit=1
ID: 78173
Patch added by: asher.baker@tripleplay.tv
Reported by: asher dot baker at tripleplay dot tv
Summary: XML-RPC mutates immutable objects during encoding
Status: Open
Type: Bug
Package: XMLRPC-EPI related
Operating System: Linux CentOS 7
PHP Version: 7.2.19
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Fix XML-RPC changing immutable hash tables
On GitHub: https://github.com/php/php-src/pull/4285
Patch: https://github.com/php/php-src/pull/4285.patch
Previous Comments:
------------------------------------------------------------------------
[2019-06-17 09:16:06] asher dot baker at tripleplay dot tv
Description:
------------
With opcache.protect_memory=1 enabled, the XML-RPC extension causes a segfault on PHP 7.2 as it is
modifying the recursion counter of objects it touches, without first checking if they are immutable
or not.
https://github.com/php/php-src/blob/28808ca96d202e63db0c407548f4fb7d4cb46d9f/ext/xmlrpc/xmlrpc-epi-php.c#L573-L575
It was fixed for 7.3 by the general recursion check refactoring: https://github.com/php/php-src/commit/cb9d81ef4f07f82835273800b0cb3d6a67816050#diff-b55aaf035c39d54c37c0f9bcc0ece5c8
It looks like this just needs some ZEND_HASH_APPLY_PROTECTION checks for 7.2
By the way, I ran into this debugging a related issue where we're seeing the nApplyCount of the
shared empty array getting incremented and staying that way (but I don't know how to reproduce
that yet), poisoning it for the rest of the process lifetime. Could this code ever leave the count
unbalanced? or is it "harmless" as it will always be back to 0 upon finishing?
Many thanks for looking at this, apologies for not having a test script but I don't know enough
about XML-RPC to extract one.
php-xmlrpc-7.2.19-2.el7.remi.x86_64
Actual result:
--------------
#0 PHP_to_XMLRPC_worker (key=key@entry=0x0, in_val=in_val@entry=0x7ffec63de950, depth=5,
depth@entry=0) at /usr/src/debug/php-7.2.19/ext/xmlrpc/xmlrpc-epi-php.c:574
#1 0x00007fd26e3958a3 in PHP_to_XMLRPC (root_val=0x7ffec63de950) at
/usr/src/debug/php-7.2.19/ext/xmlrpc/xmlrpc-epi-php.c:607
#2 php_xmlrpc_callback (server=<optimized out>, xRequest=0x7fd27aa704b0, data=0x7ffec63de920)
at /usr/src/debug/php-7.2.19/ext/xmlrpc/xmlrpc-epi-php.c:911
#3 0x00007fd26e395a70 in zif_xmlrpc_server_call_method (execute_data=<optimized out>,
return_value=0x7fd27aa20390) at /usr/src/debug/php-7.2.19/ext/xmlrpc/xmlrpc-epi-php.c:1082
#4 0x00007fd27bdd9acb in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER () at
/usr/src/debug/php-7.2.19/Zend/zend_vm_execute.h:617
#5 execute_ex (ex=0x7fd27aa00040) at /usr/src/debug/php-7.2.19/Zend/zend_vm_execute.h:59750
#6 0x00007fd27bddf63e in zend_execute (op_array=op_array@entry=0x7fd27aa641c0,
return_value=return_value@entry=0x7fd261706988)
at /usr/src/debug/php-7.2.19/Zend/zend_vm_execute.h:63776
#7 0x00007fd27bd2d033 in zend_execute_scripts (type=2057437840, type@entry=8,
retval=0x7fd261706988, retval@entry=0x0, file_count=file_count@entry=3)
at /usr/src/debug/php-7.2.19/Zend/zend.c:1498
#8 0x00007fd27bcc7848 in php_execute_script (primary_file=primary_file@entry=0x7ffec63e0e80) at
/usr/src/debug/php-7.2.19/main/main.c:2594
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78173&edit=1