Bug #77638 [Opn->Ver]: var_export on an FFI\CData:* instance causes a segmentation fault

From: Date: Mon, 21 Oct 2019 11:53:38 +0000
Subject: Bug #77638 [Opn->Ver]: var_export on an FFI\CData:* instance causes a segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223336@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77638&edit=1

 ID:                 77638
 Updated by:         cmb@php.net
 Reported by:        tandre@php.net
 Summary:            var_export on an FFI\CData:* instance causes a
                     segmentation fault
-Status:             Open
+Status:             Verified
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Linux
 PHP Version:        Next Minor Version
 Block user comment: N
 Private report:     N

 New Comment:

The problem is that the get_properties handler returns a pointer
to a const Hashtable[1], which we're trying to modify in
php_var_export_ex().

[1] <https://github.com/php/php-src/blob/d608ac6ee917c1da75868bd9cf40d5029d5e8a18/ext/ffi/ffi.c#L4699>


Previous Comments:
------------------------------------------------------------------------
[2019-02-18 18:35:27] tandre@php.net

Description:
------------
Whenever var_export() is called on the result of FFI::new(), PHP segfaults.

I think it's related to calling GC_PROTECT_RECURSION, *but the line numbers in my build may be
wrong*

```
 553                                             GC_PROTECT_RECURSION(myht);
(gdb) bt
#0  0x0000000000944811 in php_var_export_ex (struc=0x7fffecc13100, level=1, buf=0x7fffffffbf90) at
/path/to/php-src/ext/standard/var.c:553
#1  0x0000000000944fe3 in zif_var_export (execute_data=0x7fffecc130b0, return_value=0x7fffffffbfe0)
at /path/to/php-src/ext/standard/var.c:622
#2  0x0000000000bb2b63 in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER () at
/path/to/php-src/Zend/zend_vm_execute.h:649
```

Test script:
---------------
```
» php -a
Interactive shell

php > $x = FFI::new('int');
php > echo gettype($x);
object
php > echo get_class($x);
FFI\CData
php > var_dump($x);
object(FFI\CData:int32_t)#1 (1) {
  ["cdata"]=>
  int(0)
}
php > var_export($x);
[1]    2615 segmentation fault  php -a
```

Expected result:
----------------
Either dumps the type or throws an Exception/Error for being impossible to dump

Actual result:
--------------
Segfaults


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77638&edit=1


Thread (5 messages)

« previous php.bugs (#223336) next »