Bug #78860 [NEW]: Crashes when using ZEND_OP_ARRAY_EXTENSION

From: Date: Sat, 23 Nov 2019 00:58:06 +0000
Subject: Bug #78860 [NEW]: Crashes when using ZEND_OP_ARRAY_EXTENSION
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223867@lists.php.net to get a copy of this message
From:             jtax at newrelic dot com
Operating system: Linux
PHP version:      7.4.0RC6
Package:          Reproducible crash
Bug Type:         Bug
Bug description:Crashes when using ZEND_OP_ARRAY_EXTENSION

Description:
------------
I'm trying to migrate from using op_array->reserved to
ZEND_OP_ARRAY_EXTENSION
in a PHP extension. This is recommended in the UPGRADE.INTERNALS, and I
anyway
already ran into problems with op_array reserved pointers in PHP 7.3. I
see
various crashes when using ZEND_OP_ARRAY_EXTENSION and I could nail down
two
major reasons for those crashes.

1. The run time cache that ZEND_OP_ARRAY_EXTENSION accesses is not
always 
   initialized, and ZEND_OP_ARRAY_EXTENSION does no safety checks around
that.

   I can mitigate this by calling zend_fetch_function for all functions
that I
   need to access (zend_fetch_function ensures that the run time cache
is
   initialized), however there's no similar way to ensure an initialized
run
   time cache for class methods or callables.

   To transition from op_array->reserved to ZEND_OP_ARRAY_EXTENSION, I
would
   need a way to ensure that the run time cache on the op_array is
initialized.
   This could be an API function that I can call. There exists a
function
   init_func_run_time_cache in Zend, but it's static and not part of the
public
   API.

2. In one cases (namely in zend_get_call_trampoline_func), the run time
cache
   pointer is set to a dummy value of 0x2. Accessing this op_array with

   ZEND_OP_ARRAY_EXTENSION causes a crash.

   I'd expect ZEND_OP_ARRAY_EXTENSION to check for this special
condition and
   handle it accordingly.

The one critical necessary for me (and I think for many others) to
transition
from op_array->reserved to ZEND_OP_ARRAY_EXTENSION is a way to ensure an

initialized run time cache on an op_array, like a function 
init_func_run_time_cache that I can call. Enhanced safety checks in
ZEND_OP_ARRAY_EXTENSION would be a nice-to-have.



-- 
Edit bug report at https://bugs.php.net/bug.php?id=78860&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=78860&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=78860&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=78860&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=78860&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=78860&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=78860&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=78860&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=78860&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=78860&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=78860&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78860&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=78860&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=78860&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=78860&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=78860&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=78860&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=78860&r=mysqlcfg


Thread (6 messages)

« previous php.bugs (#223867) next »