Bug #78860 [NEW]: Crashes when using ZEND_OP_ARRAY_EXTENSION
From: jtax at newrelic dot com
Operating system: Linux
PHP version: 7.4.0RC6
Package: Reproducible crash
Bug Type: Bug
Bug description:Crashes when using ZEND_OP_ARRAY_EXTENSION
Description:
------------
I'm trying to migrate from using op_array->reserved to
ZEND_OP_ARRAY_EXTENSION
in a PHP extension. This is recommended in the UPGRADE.INTERNALS, and I
anyway
already ran into problems with op_array reserved pointers in PHP 7.3. I
see
various crashes when using ZEND_OP_ARRAY_EXTENSION and I could nail down
two
major reasons for those crashes.
1. The run time cache that ZEND_OP_ARRAY_EXTENSION accesses is not
always
initialized, and ZEND_OP_ARRAY_EXTENSION does no safety checks around
that.
I can mitigate this by calling zend_fetch_function for all functions
that I
need to access (zend_fetch_function ensures that the run time cache
is
initialized), however there's no similar way to ensure an initialized
run
time cache for class methods or callables.
To transition from op_array->reserved to ZEND_OP_ARRAY_EXTENSION, I
would
need a way to ensure that the run time cache on the op_array is
initialized.
This could be an API function that I can call. There exists a
function
init_func_run_time_cache in Zend, but it's static and not part of the
public
API.
2. In one cases (namely in zend_get_call_trampoline_func), the run time
cache
pointer is set to a dummy value of 0x2. Accessing this op_array with
ZEND_OP_ARRAY_EXTENSION causes a crash.
I'd expect ZEND_OP_ARRAY_EXTENSION to check for this special
condition and
handle it accordingly.
The one critical necessary for me (and I think for many others) to
transition
from op_array->reserved to ZEND_OP_ARRAY_EXTENSION is a way to ensure an
initialized run time cache on an op_array, like a function
init_func_run_time_cache that I can call. Enhanced safety checks in
ZEND_OP_ARRAY_EXTENSION would be a nice-to-have.
--
Edit bug report at https://bugs.php.net/bug.php?id=78860&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=78860&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78860&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78860&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78860&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78860&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78860&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78860&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78860&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78860&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78860&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78860&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=78860&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78860&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78860&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78860&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78860&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78860&r=mysqlcfg
Thread (6 messages)
- jtax at newrelic dot com