Bug #78231 [NEW]: Segmentation fault upon stream_socket_accept of exported socket-to-stream
| From: | asmqb7 at gmail dot com | Date: | Sat, 29 Jun 2019 06:05:40 +0000 |
| Subject: | Bug #78231 [NEW]: Segmentation fault upon stream_socket_accept of exported socket-to-stream | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-221561@lists.php.net to get a copy of this message | ||
From: asmqb7 at gmail dot com
Operating system: Linux
PHP version: 7.3.6
Package: Sockets related
Bug Type: Bug
Bug description:Segmentation fault upon stream_socket_accept of exported socket-to-stream
Description:
------------
Due to lack of documentation about the fact that SO_REUSEADDR is
unconditionally set when stream_socket_server() is used, I thought I
would need to use the socket_* functions to set the option on a stream
I'd already created.
I figured I could then export the newly-bound socket to a stream, and
proceed from there without needing to use any other socket_* functions,
which I try to avoid using as I've been bitten by the sockets extension
in the past (other bugs etc).
Well, I'm not quite sure what I broke this time, but the attached test
script segfaults on my system with 100% consistency. I suspect the code
path that handles "stream bound by the sockets library, exported, then
selected on by the streams subsystem" is probably un[der?]implemented.
It's not visible yet, but I added some info to the notes section at
http://php.net/socket_set_option, which is what
shows up most
prominently when googling SO_REUSEADDR in the context of PHP.
Test script:
---------------
<?php
$port = 55555;
$socket = socket_create(AF_INET, SOCK_STREAM, SOL_TCP);
print '$socket: '; var_dump($socket);
print 'socket_bind(): ';
var_dump(socket_bind($socket, '127.0.0.1', $port));
$listening_fd = socket_export_stream($socket);
print 'socket_export_stream(): ';
var_dump($listening_fd);
for (;;) {
$read = $write = $except = [];
$read[] = $listening_fd;
stream_select($read, $write, $except, null);
foreach ($read as $fd) {
switch ($fd) {
case $listening_fd:
print "stream_socket_accept() on: "; var_dump($fd);
$new_fd = stream_socket_accept($fd);
}
}
}
Expected result:
----------------
For a stream exported from a socket to behave identically to a stream
created by the streams functionality, and particularly for untested
codepaths to not cause runtime segfaults.
Actual result:
--------------
$socket: resource(4) of type (Socket)
socket_bind(): bool(true)
socket_export_stream(): resource(5) of type (stream)
stream_socket_accept() on: resource(5) of type (stream)
Program received signal SIGSEGV, Segmentation fault.
0x00005555558ce3b6 in php_stream_context_get_option ()
(gdb) bt
#0 0x00005555558ce3b6 in php_stream_context_get_option ()
#1 0x00005555556df1bc in ?? ()
#2 0x00005555558cc72d in _php_stream_set_option ()
#3 0x00005555558d6560 in php_stream_xport_accept ()
#4 0x0000555555884378 in ?? ()
#5 0x0000555555994a85 in execute_ex ()
#6 0x000055555599aaf6 in zend_execute ()
#7 0x00005555559136aa in zend_execute_scripts ()
#8 0x00005555558b35c9 in php_execute_script ()
#9 0x000055555599d0f6 in ?? ()
#10 0x000055555569e0a7 in ?? ()
#11 0x00007ffff72abce3 in __libc_start_
--
Edit bug report at https://bugs.php.net/bug.php?id=78231&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=78231&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=78231&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=78231&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=78231&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78231&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78231&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78231&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78231&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78231&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78231&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78231&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78231&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78231&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=78231&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=78231&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78231&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78231&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78231&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78231&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78231&r=mysqlcfg